Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. Attackers can submit crafted payloads like '=10+20+cmd|' /C calc'!A0' in the message field to trigger arbitrary command execution when the CSV is opened in spreadsheet applications.
References
| Link | Resource |
|---|---|
| https://github.com/tendenci/tendenci | Product |
| https://www.exploit-db.com/exploits/49145 | Exploit Third Party Advisory VDB Entry |
| https://www.tendenci.com/ | Product |
| https://www.vulncheck.com/advisories/tendenci-csv-formula-injection | Third Party Advisory |
| https://www.exploit-db.com/exploits/49145 | Exploit Third Party Advisory VDB Entry |
Configurations
History
02 Feb 2026, 19:13
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Tendenci
Tendenci tendenci |
|
| CPE | cpe:2.3:a:tendenci:tendenci:12.3.1:*:*:*:*:*:*:* | |
| References | () https://github.com/tendenci/tendenci - Product | |
| References | () https://www.exploit-db.com/exploits/49145 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://www.tendenci.com/ - Product | |
| References | () https://www.vulncheck.com/advisories/tendenci-csv-formula-injection - Third Party Advisory |
29 Jan 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/49145 - |
28 Jan 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-28 18:16
Updated : 2026-02-02 19:13
NVD link : CVE-2020-36962
Mitre link : CVE-2020-36962
CVE.ORG link : CVE-2020-36962
JSON object : View
Products Affected
tendenci
- tendenci
CWE
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
