CVE-2018-25135

Publication date

2025-12-24 19:27:45

Family

VulnCheck

State

PUBLISHED

Description

Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like Name, Gender, or Position to trigger Excel macro execution when importing user data.