CVE-2020-12468
Subrion CMS 4.2.1 allows CSV injection via a phrase value within a language. This is related to phrases/add/ and languages/download/.
Date published : 2020-04-29
https://github.com/belong2yourself/vulnerabilities/tree/master/Subrion%20CMS/CSV%20Injection