<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CSV Injection on Saksham Anand</title>
    <link>/tags/csv-injection/</link>
    <description>Recent content in CSV Injection on Saksham Anand</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 03 Nov 2021 00:00:00 +0000</lastBuildDate>
    <atom:link href="/tags/csv-injection/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>CVE-2021-40848 Mahara | CSV Injection</title>
      <link>/blog/cve-2021-40848/</link>
      <pubDate>Wed, 03 Nov 2021 00:00:00 +0000</pubDate>
      <guid>/blog/cve-2021-40848/</guid>
      <description>Mahara is an electronic portfolio system that is used as an eLearning tool by education institutions around the globe. The software contains the ability to export records from the system into a CSV file. This blog will cover how that functionality can be abused (when inputs are not escaped correctly), to conduct local command execution (aka CSV injection).
For this demonstration, two accounts will be used. The first account will be the malicious actor where CSV injection payloads are saved into editable inputs.</description>
    </item>
  </channel>
</rss>
