The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/300ebfcd-c500-464e-b919-acfeb72593de/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/300ebfcd-c500-464e-b919-acfeb72593de/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-01-16 16:15
Updated : 2024-11-21 07:19
NVD link : CVE-2022-3604
Mitre link : CVE-2022-3604
CVE.ORG link : CVE-2022-3604
JSON object : View
Products Affected
crmperks
- database_for_contact_form_7\,_wpforms\,_elementor_forms
CWE
CWE-1236
Improper Neutralization of Formula Elements in a CSV File