Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x6c4-gw3r-222g

Опубликовано: 26 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.

The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.

EPSS

Процентиль: 76%
0.00967
Низкий

8.8 High

CVSS3

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.

EPSS

Процентиль: 76%
0.00967
Низкий

8.8 High

CVSS3

Дефекты

CWE-1236