CVE-2025-60852

A CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built with affected versions of the framework did not properly sanitize user-controlled input before including it in CSV exports. This issue could lead to code execution on the system where the exported CSV file is opened.
Configurations

No configuration.

History

23 Oct 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-1236

23 Oct 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-23 14:15

Updated : 2025-10-23 17:15


NVD link : CVE-2025-60852

Mitre link : CVE-2025-60852

CVE.ORG link : CVE-2025-60852


JSON object : View

Products Affected

No product.

CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File