Impact
The vulnerability exists in the CSV export functionality of Brainstorm Force SureForms versions 2.12.1 and earlier. User‑controlled form field names are written to the CSV without neutralizing spreadsheet formula characters before generation. An attacker can craft malicious field names that embed spreadsheet formulas; when an administrator opens the resulting CSV file in a spreadsheet application that automatically evaluates formulas, the attacker gains the ability to execute the spreadsheet formulas on the administrator’s workstation. These formulas can lead to arbitrary code execution or data exfiltration, providing a direct pathway to compromise the administrator’s environment.
Affected Systems
Any installation of SureForms running version 2.12.1 or earlier that uses the CSV export feature is affected. The flaw is present in all deployments where form submissions are exported to CSV without additional filtering or sanitization.
Risk and Exploitability
The EPSS score indicates an exploitation probability of less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no large‑scale exploitation has been reported. Exploitation requires an attacker to create malicious form submissions and an administrator to download and open the exported CSV in a spreadsheet application that automatically evaluates formulas. While the risk is confined to situations where administrators handle these files, the impact is severe enough to warrant prompt remediation.
OpenCVE Enrichment