Description
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-24835 | The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks. |
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T00:10:03.492Z
Reserved: 2022-04-29T00:00:00.000Z
Link: CVE-2022-1539
No data.
Status : Modified
Published: 2022-07-25T13:15:08.163
Modified: 2024-11-21T06:40:55.723
Link: CVE-2022-1539
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD