[inventree] Formula Injection in Exported Data

Impact
Datasets exported to file (e.g. CSV / XLS) are not sufficiently sanitized, to neutralize potential formula injection
Patches

The issue is addressed in the upcoming 0.8.0 release
This fix will also be back-ported to the 0.7.x branch, applied to …

[inventree] Unrestricted Attachment Upload

Impact
InvenTree allows unrestricted upload of files as attachments to various database fields. Potentially dangerous files (such as HTML files containing malicious javascript) can be uploaded, and (when opened by the user) run the malicious code direc…