A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as his first or last name, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.
History

Tue, 15 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-11-08T18:00:17

Updated: 2024-10-15T18:36:35.309Z

Reserved: 2019-10-16T00:00:00

Link: CVE-2019-17661

cve-icon Vulnrichment

Updated: 2024-08-05T01:47:13.470Z

cve-icon NVD

Status : Modified

Published: 2019-11-08T18:15:13.527

Modified: 2024-11-21T04:32:43.430

Link: CVE-2019-17661

cve-icon Redhat

No data.