Neutralize CSV formula injection in generated exports using the new created escapeCsvFormula Function

This commit is contained in:
johnnyq
2026-07-24 18:12:45 -04:00
parent 28f1a965b8
commit 5c4805b822
21 changed files with 48 additions and 23 deletions

View File

@@ -450,7 +450,7 @@ if (isset($_POST['export_credentials_csv'])) {
$credential_username = decryptCredentialEntry($row['credential_username']);
$credential_password = decryptCredentialEntry($row['credential_password']);
$lineData = array($row['credential_name'], $row['credential_description'], $credential_username, $credential_password, $row['credential_otp_secret'], $row['credential_uri']);
fputcsv($f, $lineData, $delimiter, $enclosure, $escape);
fputcsv($f, array_map('escapeCsvFormula', $lineData), $delimiter, $enclosure, $escape);
}
//move back to beginning of file