CVE-2018-25135CWE-149

Anviz AIM CrossChex Standard 4.3.6.0 CSV Injection via User Import

Critical 路 published December 24, 2025

CVSS v4.0
9.3
EPSS
1%
Percentile
50.3
In the wild
Unconfirmed
What it is

馃敟 A crafty CSV injection vulnerability lets attackers unleash their commands the moment you import user data! 馃毃 Think of it like a sneaky waiter slipping a surprise ingredient into a recipe just as you're about to enjoy your meal. If you're not paying attention, that hidden formula could ruin the whole dish! An attacker can manipulate fields like 'Name' or 'Gender' to execute malicious commands, potentially compromising your entire system. This is critical because it opens the door for attackers to run harmful macros right under your nose when you try to import what you think is safe user data. The damage could be devastating!

Put simply

Think of it like a sneaky waiter slipping a surprise ingredient into a recipe just as you're about to enjoy your meal. If you're not paying attention, that hidden formula could ruin the whole dish! This vulnerability occurs when the Anviz AIM CrossChex Standard software fails to properly validate input in CSV files, allowing attackers to insert harmful Excel formulas that execute upon import.

What to do

An attacker can manipulate fields like 'Name' or 'Gender' to execute malicious commands, potentially compromising your entire system. This is critical because it opens the door for attackers to run harmful macros right under your nose when you try to import what you think is safe user data. The damage could be devastating! Immediate steps: Upgrade to version 4.3.6.1 to patch this vulnerability, review your CSV handling processes, and ensure strict input validation for any fields that accept user data. Always be wary of external data sources! You've got this! By taking these steps, you'll be a security hero, keeping your systems safe from CSV chaos! 馃Ω

The record
Technical detail
CVSS v4.0
9.3 路 CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00686 路 50.3th percentile
Weakness
CWE-149 路 Improper Neutralization of Quoting Syntax
Published
2025-12-24T19:27Z
EPSS history
Timeline
  • 24 DEC 19:27Z
    Anviz AIM CrossChex Standard 4.3.6.0 CSV Injection via User Import
    cvelistv5