{"id":"CVE-2018-25135","title":"Anviz AIM CrossChex Standard 4.3.6.0 CSV Injection via User Import","summary":"Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like 'Name', 'Gender', or…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-149"],"vendor":"Anviz Biometric Technology Co., Ltd.","product":"Anviz AIM CrossChex Standard","affected":["anviz_aim_crosschex_standard 4.3"],"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"total","timestamp":"2025-12-24T20:13:27.766153Z"},"exploitAvailable":true,"published":"2025-12-24","updated":"2026-10-01","sourceUpdated":"2026-10-01T21:44:50.789Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2018-25135","references":[{"url":"https://www.exploit-db.com/exploits/45765","label":"ExploitDB-45765"},{"url":"https://www.anviz.com","label":"Anviz Biometric Technology Product Homepage"},{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5498.php","label":"Zero Science Lab Disclosure (ZSL-2018-5498)"}],"tags":["cve.org","exploit-available"],"epss":0.00702,"epssPercentile":0.51514,"ingestedAt":"2026-10-01T23:03:32.845Z","slug":"CVE-2018-25135","body":"## Overview\n\nAnviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like 'Name', 'Gender', or 'Position' to trigger Excel macro execution when importing user data.\n\n## Affected\n\n- `anviz_aim_crosschex_standard 4.3`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}