Impact
Improper encoding or escaping of output allows an authenticated user to embed a spreadsheet formula in their own plain attributes. When such an attribute is exported in a CSV file and opened with a spreadsheet application, the malicious formula can be executed by the end‑user, giving the attacker the ability to run arbitrary code or exfiltrate data from the target machine.
Affected Systems
Affected products are Apache Syncope from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, and from 4.1.0-M0 through 4.1.2. These releases are provided by the Apache Software Foundation and ship with the vulnerable export logic that does not encode special characters.
Risk and Exploitability
The CVSS score of the vulnerability is 7.3, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because an attacker must first be authenticated to store malicious formula payloads, the risk is limited to users with write access to their profile attributes. Nonetheless, if an end‑user opens a malicious CSV in a spreadsheet application, the embedded formula can execute arbitrary code or exfiltrate data from the target machine, making this a serious concern especially where spreadsheets are trusted.
OpenCVE Enrichment