Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2mcr-fc8f-ffp4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable.

Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable.

EPSS

Процентиль: 77%
0.01048
Низкий

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable.

EPSS

Процентиль: 77%
0.01048
Низкий

Дефекты

CWE-74