Settings

Theme

The Underestimated Dangers of CSV Injection

georgemauer.net

3 points by MarcellusDrum 2 years ago · 1 comment

Reader

maplet 2 years ago

The article is 6 years old but the CSV Injection still works on Google Sheets and Excel. (I imported the example csv file into both platforms and the equations were executed)

Great reminder to be vigilant. Pride cometh before a fall:

> Are they a technically savvy user? Then it is even worse. They know the CSV format is just text data, there can’t possibly be anything harmful in there. Guaranteed.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection