CVE-2018-20468: Sahipro Sahi Pro
High severity, CVSS 8.8. EPSS: 2.2% chance of exploitation in the next 30 days.
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" that are vulnerable to CSV injection. An attacker can embed Excel formulas inside an automation script that, when exported after execution, results in code execution.
Affected products
- Sahipro Sahi Pro: up to and including 8.0.0
Published 2019-06-17. Last modified 2026-06-17.