{"id":"CVE-2020-36962","title":"Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export","summary":"Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. Attackers can submit crafted payloads like '=10+20+cmd|' /C calc'!A0' in t…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-1236"],"vendor":"tendenci","product":"tendenci","affected":["tendenci = 12.3.1"],"published":"2026-01-28","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:16:44.033","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-36962","references":[{"url":"https://github.com/tendenci/tendenci","label":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/49145","label":"disclosure@vulncheck.com"},{"url":"https://www.tendenci.com/","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/tendenci-csv-formula-injection","label":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/49145","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-01-28T20:01:26.865256Z"},"epss":0.12193,"epssPercentile":0.96066,"ingestedAt":"2026-10-08T16:52:14.671Z","slug":"CVE-2020-36962","body":"## Overview\n\nTendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. Attackers can submit crafted payloads like '=10+20+cmd|' /C calc'!A0' in the message field to trigger arbitrary command execution when the CSV is opened in spreadsheet applications.\n\n## Affected\n\n- `tendenci = 12.3.1`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":68,"depthScoreParts":{"impact":53.9,"likelihood":2.4,"exploitation":12,"ransomware":0},"changes":[]}