Back to overview

CVE-2020-36941

CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
Knockpy 4.1.1 contains a CSV injection vulnerability that allows attackers to inject malicious formulas into CSV reports through unfiltered server headers. Attackers can manipulate server response headers to include spreadsheet formulas that will execute when the CSV is opened in spreadsheet applications.

Metadata

CVE ID
CVE-2020-36941
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-01-25 13:50 UTC
Published
2026-01-27 15:23 UTC
Last updated
2026-03-05 01:27 UTC
Primary CWE
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
Vendor / Product
guelfoweb / knock
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
guelfoweb knock 4.1.1
Weakness (CWE)
CWESourceDescription
CWE-1236 cna Improper Neutralization of Formula Elements in a CSV File
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
5.3 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
References (3)
Back to overview