The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file and not TablePress.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-10734 The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file and not TablePress.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T02:39:09.816Z

Reserved: 2019-12-31T00:00:00

Link: CVE-2019-20180

cve-icon Vulnrichment

Updated: 2024-08-05T02:39:09.816Z

cve-icon NVD

Status : Modified

Published: 2020-01-09T21:15:11.933

Modified: 2024-11-21T04:38:10.327

Link: CVE-2019-20180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.