Skip to content

Add that CSV Injection can be caused by a double-byte characters. #1088

@k163377

Description

@k163377

The CSV Injection can also be caused by a double-byte characters(, , , ).
For example, =cmd|’ /C calc'!A0 is reproduced when executed in a Japanese environment.

This is not mentioned on this page, but I think it should be mentioned explicitly.
https://github.com/OWASP/www-community/blob/master/pages/attacks/CSV_Injection.md

However, I submitted this issue because I did not know what kind of verification was needed to add it, what words to choose, etc.
I apologize that I do not have Excel myself and can only help a little.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions