Improper Neutralization of Formula Elements in a CSV File

Summary

An improper neutralization of formula elements in a CSV file vulnerability [CWE-1236] in FortiSOAR may allow a remote authenticated attacker with user privileges to inject a malicious payload as a table record that can get executed on the target's machine upon being exported as a file by a high privileged user.

Version Affected Solution
FortiSOAR on-premise 7.6 Not affected Not Applicable
FortiSOAR on-premise 7.5 Not affected Not Applicable
FortiSOAR on-premise 7.4 7.4.0 through 7.4.1 Upgrade to 7.4.2 or above
FortiSOAR on-premise 7.3 7.3.0 through 7.3.2 Upgrade to 7.3.3 or above
FortiSOAR on-premise 7.2 7.2.1 through 7.2.2 Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Hritik Sateesh from Burnaby InfoSec team.

Timeline

2025-01-14: Initial publication