{"id":"CVE-2026-47693","aliases":["GHSA-3h6h-67x3-cv5x"],"title":"Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications","summary":"Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications","severity":"medium","cvss":6.9,"cwe":["CWE-1236"],"vendor":"poweradmin","product":"poweradmin/poweradmin","ecosystem":"composer","affected":["poweradmin/poweradmin < 4.2.4","poweradmin/poweradmin >= 4.3.0, < 4.3.3"],"patched":["poweradmin/poweradmin 4.2.4","poweradmin/poweradmin 4.3.3"],"published":"2026-06-08","updated":"2026-06-08","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-3h6h-67x3-cv5x","references":[{"url":"https://github.com/poweradmin/poweradmin/security/advisories/GHSA-3h6h-67x3-cv5x"},{"url":"https://github.com/poweradmin/poweradmin/releases/tag/v4.2.4"},{"url":"https://github.com/poweradmin/poweradmin/releases/tag/v4.3.3"},{"url":"https://github.com/advisories/GHSA-3h6h-67x3-cv5x"}],"tags":["ghsa","composer"],"epss":0.00375,"epssPercentile":0.31267,"ingestedAt":"2026-07-07T15:41:59.845Z","slug":"CVE-2026-47693","body":"## Overview\n\nDescription:\n\n### Summary\n\nPoweradmin v4.4.0 is vulnerable to CSV Injection (Formula Injection) in its log export functionality. User-controlled data — specifically the username field — is written to exported CSV files without sanitizing formula trigger characters (=, +, -, @). When an administrator exports activity logs and opens the resulting CSV in a spreadsheet application (Microsoft Excel, LibreOffice Calc, Google Sheets), any formula stored in a username is executed by the application. This can be used for phishing attacks against administrators or data exfiltration.\n\n### Details\n\nThe vulnerability exists in all four log export controllers:\n\n- `lib/Application/Controller/ListLogUsersController.php` (lines 188, 194)\n- `lib/Application/Controller/ListLogZonesController.php`\n- `lib/Application/Controller/ListLogGroupsController.php`\n- `lib/Application/Controller/ListLogApiController.php`\n\nThese controllers export database rows via `fputcsv()` without applying any formula injection countermeasures. The `user` column contains the username of the actor who performed the operation, and the `username` column (in user logs) contains the username of the affected account. Both fields are written verbatim to the CSV output.\n\nA username such as `=1+1` is written **without CSV enclosure quotes** (because it contains no commas or quotes), so spreadsheet applications treat it directly as a formula. A username containing commas or quotes (e.g. `=HYPERLINK(\"http://attacker.com\",\"Click here\")`) is enclosed in CSV quotes with internal quotes doubled, but spreadsheet applications still evaluate the cell value as a formula since it begins with `=`.\n\nAdditionally, PHP deprecation warnings are emitted directly into the HTTP response body before CSV headers, exposing internal file paths (e.g. `/app/lib/Application/Controller/ListLogUsersController.php`) — a secondary information disclosure issue (CWE-209). This also corrupts the CSV file when PHP error reporting is enabled.\n\n### PoC\n\n**Prerequisites:** An account with `user_add_new` permission (administrator role).\n\n**Steps to reproduce:**\n\n1. Log in as administrator.\n2. Navigate to Add User and create an account with:\n   - Username: `=HYPERLINK(\"http://attacker.com\",\"Confirm Identity\")`\n   - Any valid email and password\n3. Log out, then log in with the newly created account to generate a log entry.\n4. Log back in as administrator.\n5. Navigate to `/users/logs` and click Export CSV.\n6. Open the downloaded CSV file in Microsoft Excel or LibreOffice Calc.\n\n**Result:** Excel renders a clickable hyperlink labeled \"Confirm Identity\" pointing to `http://attacker.com` in the `user` column of the log entry. With the simpler username `=1+1`, the cell displays `2` instead of the literal text, confirming formula execution.\n\nConfirmed on Poweradmin v4.4.0 (Docker image `poweradmin/poweradmin:latest`).\n\n### Impact\n\nThis is a CSV Injection vulnerability (CWE-1236). It affects any administrator who exports activity logs to CSV and opens the file in a spreadsheet application.\n\n**Attack scenarios:**\n\n- **Phishing:** A malicious actor with the ability to create user accounts sets a formula username that renders as a convincing link in the exported report, tricking a higher-privileged administrator into clicking it.\n- **Data exfiltration:** Using `=IMPORTXML()` in Google Sheets or similar, adjacent cell data (log contents) can be sent to an attacker-controlled server silently when the sheet is opened.\n\n## Affected packages\n\n- `poweradmin/poweradmin < 4.2.4`\n- `poweradmin/poweradmin >= 4.3.0, < 4.3.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `poweradmin/poweradmin 4.2.4`\n- `poweradmin/poweradmin 4.3.3`","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":38,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}