Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-686c-xjjw-8474

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.

The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.

EPSS

Процентиль: 93%
0.10725
Средний

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.8
nvd
почти 6 лет назад

The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.

EPSS

Процентиль: 93%
0.10725
Средний

Дефекты

CWE-20