Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-68xc-xqw9-7x6f

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.

The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.

EPSS

Процентиль: 95%
0.1934
Средний

Дефекты

CWE-1236
CWE-74

Связанные уязвимости

CVSS3: 7.8
nvd
почти 6 лет назад

The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.

EPSS

Процентиль: 95%
0.1934
Средний

Дефекты

CWE-1236
CWE-74