216.73.217.22

CVE-2023-54348

· Published 05/05/2026 12:16 · Modified 05/05/2026 19:50

Labels: CVE-2023-54348 2026-05-05CVE-2023-54348CWE-1236[email protected]

Essential information

Published
05/05/2026 12:16
Modified
05/05/2026 19:50
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to execute arbitrary code by injecting formula payloads into vendor name fields. Attackers can add malicious formulas like =10+20+cmd|' /C calc'!A0 in the vendor creation form, which execute when the exported CSV file is opened in spreadsheet applications.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
erpgo / erpgo saas cpe:2.3:a:erpgo:erpgo_saas:3.9:*:*:*:*:*:*:*

References