Fedora Account System
Red Hat Associate
Red Hat Customer
Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or gain access to information when a user opens the csv_export.php generated CSV file in Excel. https://www.mantisbt.org/bugs/view.php?id=29130 https://github.com/mantisbt/mantisbt/commit/7f4534c723e3162b8784aebda4836324041dbc3e
Created mantis tracking bugs for this issue: Affects: fedora-all [bug 2076142]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.