CVE-2021-25962

“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed.

Date published : 2021-09-29

https://github.com/shuup/shuup/commit/0a2db392e8518410c282412561461cd8797eea51

https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25962