Impact
The flaw is an improper neutralization of formula elements inside a CSV file processed by MIA Technology Inc.'s Pizzy Library. Because the library accepts raw CSV input, a maliciously crafted file can cause injected code to execute during parsing, allowing an attacker to compromise confidentiality, integrity, or availability of any system that uses the library to load that file. The weakness is categorized as CWE‑1236 and carries a CVSS score of 8.8.
Affected Systems
Affecting MIA Technology Inc.'s Pizzy Library versions from 1.0.0.26250 up to, but not including, 1.3.9.26250 on all platforms where the library is deployed. No other products or versions are listed as affected.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is considered critically high severity. The EPSS score is not publicly available, indicating that detailed exploitation probability data is missing; however, the lack of a KEV listing suggests it has not been widely leveraged in the wild to date. The likely attack vector is a file upload or import scenario where an attacker supplies a malicious CSV to the application that utilizes Pizzy Library, leading to code execution without additional authentication or privilege escalation mechanisms.
OpenCVE Enrichment