CVE-2023-41798
The Directorist plugin before version 7.7.2 contains a CSV injection vulnerability that enables attackers to embed malicious formulas into exported CSV files, potentially leading to command execution or exploitation of spreadsheet applications on users' computers. This flaw, discovered by Rafshanzani Suhada, remains unpatched as of the advisory date. An attacker could craft specially designed input to inject these formulas, which would execute when a victim opens the resulting CSV file in spreadsheet software. The vulnerability affects all versions below 7.7.2 with no available patch.
Based on public CVE data (MITRE/NVD).