Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-7947

Опубликовано: 01 апр. 2020
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting of the user data. This can lead to (at least) CSV injection if a crafted Excel document is uploaded.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:auth0:login_by_auth0:*:*:*:*:*:wordpress:*:*
Версия до 4.0.0 (исключая)

EPSS

Процентиль: 82%
0.01807
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-1236

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting of the user data. This can lead to (at least) CSV injection if a crafted Excel document is uploaded.

EPSS

Процентиль: 82%
0.01807
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-1236