Description An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection. Remediation References CVE-2019-12765 Related Vulnerabilities IBM WebSEAL Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-1740) WordPress Plugin Favicon by RealFaviconGenerator Cross-Site Scripting (1.2.12) WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.23) WordPress Plugin Qiniu Uploader Cross-Site Scripting (0.1) WordPress Plugin Custom 404 Pro Cross-Site Scripting (3.2.7) Severity Critical Classification CVE-2019-12765 CWE-1236 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities