Skip to main content

CVE-2025-8808: Tianti User Management CSV Injection Flaw

CVE-2025-8808 is a CSV injection flaw in Tianti user management system affecting the exportOrder function. Attackers can inject malicious formulas into CSV exports. This post covers technical details, impact analysis, and mitigation strategies.

Published:

CVE-2025-8808 Overview

A CSV injection vulnerability affects xujeff tianti (天梯) content management system versions up to 2.3. The flaw resides in the exportOrder function within /tianti-module-admin/user/ajax/save, part of the com.jeff.tianti.controller component. Attackers with low-privileged network access can inject formula payloads that execute when exported CSV files are opened in spreadsheet applications. The issue is classified under [CWE-74] as improper neutralization of special elements in output. The vendor was contacted but did not respond, and public exploit details have been disclosed.

Critical Impact

Authenticated attackers can inject malicious spreadsheet formulas that execute in the context of downstream users who open the exported CSV files.

Affected Products

  • xujeff tianti (天梯) versions up to 2.3
  • Component: com.jeff.tianti.controller
  • Endpoint: /tianti-module-admin/user/ajax/save

Discovery Timeline

  • 2025-08-10 - CVE CVE-2025-8808 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-8808

Vulnerability Analysis

The vulnerability is a CSV injection flaw in the exportOrder function of the tianti administration module. When user-controlled data is written into exported CSV files without sanitization, cells beginning with characters such as =, +, -, or @ are interpreted as formulas by spreadsheet applications like Microsoft Excel and LibreOffice Calc. This enables formula execution, data exfiltration through remote references, and in some configurations invocation of external commands via features like DDE.

The attack vector is network-based and requires low privileges but no user interaction on the vulnerable server. Exploitation impact materializes on the client side when a legitimate user opens the downloaded export file.

Root Cause

The root cause is missing output neutralization when serializing user-supplied fields into CSV rows. The exportOrder handler does not prefix leading formula trigger characters with a neutralizing single quote or apostrophe, nor does it wrap or escape values that begin with =, +, -, @, tab, or carriage return characters.

Attack Vector

An authenticated attacker submits crafted input through the /tianti-module-admin/user/ajax/save endpoint. The malicious payload is stored and later included in a CSV export generated by exportOrder. When an administrator or downstream user opens the exported file, the spreadsheet client parses the injected content as an executable formula. Public exploit details are available via the GitHub Issue Discussion and the VulDB CVE Report.

// See the referenced GitHub issue for verified proof-of-concept details.
// No sanitized exploit code is reproduced here.

Detection Methods for CVE-2025-8808

Indicators of Compromise

  • CSV files exported from tianti containing cells that begin with =, +, -, or @ in user-controlled fields.
  • Outbound network requests from spreadsheet client processes such as EXCEL.EXE immediately after opening a tianti export.
  • Unexpected child processes spawned by spreadsheet applications on analyst or administrator workstations.

Detection Strategies

  • Inspect stored user records in the tianti database for values beginning with formula trigger characters in fields destined for CSV export.
  • Monitor HTTP POST requests to /tianti-module-admin/user/ajax/save for payloads containing leading =, +, -, @, tab, or carriage return characters.
  • Review web server access logs for repeated calls to the exportOrder handler correlated with suspicious save submissions.

Monitoring Recommendations

  • Alert on spreadsheet processes initiating network connections or spawning shell interpreters such as cmd.exe or powershell.exe.
  • Track file-download events for CSV artifacts originating from the tianti admin module and correlate with subsequent user activity.
  • Enable audit logging on the com.jeff.tianti.controller component to capture input values written to exported reports.

How to Mitigate CVE-2025-8808

Immediate Actions Required

  • Restrict access to /tianti-module-admin/user/ajax/save and the export functionality to trusted administrative users only.
  • Sanitize existing stored records by prefixing any field beginning with =, +, -, @, tab, or carriage return with a single quote before regeneration of exports.
  • Instruct users to open tianti CSV exports in a controlled viewer or with formula execution disabled until a fix is applied.

Patch Information

No vendor patch is available. According to the disclosure, the vendor was contacted early but did not respond. Organizations running xujeff tianti should apply source-level input neutralization in the exportOrder function and consider migrating away from unmaintained deployments.

Workarounds

  • Wrap all exported cell values with a leading single quote when the first character is a formula trigger, effectively neutralizing spreadsheet interpretation.
  • Configure Microsoft Excel and LibreOffice Calc group policies to disable Dynamic Data Exchange (DDE) and external content execution.
  • Deliver exports in a non-executable format such as XLSX with cells typed as text, or PDF, instead of raw CSV.
bash
# Example server-side sanitization pattern (pseudo-config)
# For each cell value V destined for CSV output:
#   if V starts with '=', '+', '-', '@', 0x09, or 0x0D:
#       V = "'" + V
#   escape embedded quotes and wrap V in double quotes

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.