In this article we will explain the CSV injection technique, which exploits the “Export to Spreadsheet” function. While working on a project, this vulnerability was found in one of Microsoft’s products, CRM – Customer Relationship Management
What is CRM? :
It is a Microsoft product, used for the purpose of managing and analyzing customer interactions and data throughout the customer lifecycle, with the aim of improving business relationships with its customers.
Description:
Many web applications offer the ability to export spreadsheets, which allows an attacker to find fertile ground for their malicious code, so that when the victim downloads the csv file and opens it, the malicious code will be executed.
This is possible when a web application does not properly check the validity of input fields, so the attacker can insert some malicious code through the unvalidated input fields. As a result, the resulting spreadsheet cells contain malicious code. With the export feature, the user can download the file in .csv or .xls. This is inherently dangerous, because any cell that starts with “=” is interpreted as a formula by the spreadsheet.
[su_button url=”https://www.secnews.gr/103180/dual-boot-kali-linux-with-windows-10/” target=”blank” style=”glass” background=”#f26473″ color=”#1a211a7″ wide=”yes” center=”yes” radius=”20″ icon_color=”#ffffff”]Read also: How to dual boot Kali Linux & Windows 10!! Step-by-step[/su_button]
Successful exploitation would allow an attacker to execute arbitrary code with the privileges of the currently logged-in user on the system, causing severe damage to the victim's system, such as wiping out an entire partition or creating backdoors for later access. Many other attacks are possible, depending on the creativity of the attacker.
Exploitation Steps:
I. Login with valid user credentials and inject the malicious command (=cmd|' /C calc'!A0) into the user's “Full name” input field

II. Now create a lead and the owner will be the user's “Full name”

III. The Lead was successfully saved with the malicious code (=cmd|' /C calc'!A0) under the Owner field

IV. When the victim downloads the excel file, the malicious code will be successfully executed on the victim's system.

[alert size=”alert-block” variation=”alert-success”]SecNews.gr warmly thanks the friend of the website Fotis Tretas for the timely and accurate information[/alert]
