Описание
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
Ссылки
- ProductThird Party Advisory
- Third Party AdvisoryVDB Entry
- ProductThird Party Advisory
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 2.13.2 (включая)
cpe:2.3:a:search_meter_project:search_meter:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 93%
0.10725
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-1236
Связанные уязвимости
github
больше 3 лет назад
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
EPSS
Процентиль: 93%
0.10725
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-1236