CVE-2021-47901

Publication date

2026-01-27 15:23:52

Family

VulnCheck

State

PUBLISHED

Description

Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject formulas through redirected endpoints. Attackers can craft malicious server redirects with comma-separated paths containing Excel formulas to manipulate the generated CSV report.