Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-19501-poc — Proof-of-concept for unauthenticated CSV formula injection in SureForms, showing crafted form submissions trigger spreadsheet formulas when exported by admins. | Kitploit
Tools/GitHubGitHub/typedefabcd1234ntd/cve-2026-19501-poc
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubtypedefabcd1234ntd/cve-2026-19501-poc

CVE-2026-19501-poc

Proof-of-concept for unauthenticated CSV formula injection in SureForms, showing crafted form submissions trigger spreadsheet formulas when exported by admins.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
161 month agoNot yet reviewed
Share

CVE-2026-19501 Poc

Description:

Sureforms is vulnerabale to a unauthenticated CSV injection vulnerability when attacker can inject a CSV formula when submit a form. This formula will be excuted when admin export CSV file and open it.

Step to reproduce:

Step 1: Submit a form and then intercept the submit request

Step 2: Change the body line which include a key "srfm-input..." to

<randomtext>-lbl-<the formula in base 64>: <the content>

Example:

abcdef-lbl-PTIrNStjbWR8JyAvQyBjYWxjJyFBMA==

Step 3: Send the submit request and wait the payload to exploit when admin export and open the CSV file

How to fix

Updates to the latest version (2.12.3 or later) to solve this issue

Note

If you feel this write-up here great and interesting, you contribute me in my Github Sponsor.

Download Tool