Impact
WWBN AVideo contains a CSV formula injection flaw in the myComments.download.php endpoint comment text, allowing an attacker to insert spreadsheet formulas that start with '=', '+', '-', or '@'. When an administrator or video owner exports the comments as CSV and opens the file in a spreadsheet application, the embedded formula executes, potentially exposing or manipulating data. This weakness is a classic CSV formula injection (CWE-1236).
Affected Systems
The affected product is releases prior to commit c3edcc274c389816d434acadac07ee78eaf330c1. Any deployment that has not applied this update is susceptible. Administrators and video owners who export comment data are the ones who could trigger the payload in the myComments.download.php endpoint of WWBN AVideo, allowing an authenticated user to insert comment text that begins with spreadsheet formula prefixes (=, +, -, @). When an administrator or video owner exports comments as a CSV file and opens it in a spreadsheet, the injected formula is executed, potentially exposing sensitive data. The weakness is a classic CSV formula injection (CWE-1236).
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity with an attack vector that requires user interaction to trigger the injection. The exploit is limited to authenticated users who can create or edit comments; no publicly exploitable remote service is required. Because the vulnerability does not automatically grant attackers full control over the system, the risk is primarily local. Current EPSS data is not available, and the issue is not listed in the CISA KEV catalog. Compromised administrators could potentially expose sensitive data within the spreadsheet, leading to potential data exfiltration.
OpenCVE Enrichment