The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it
Advisories
Source ID Title
EUVD EUVD EUVD-2022-34518 The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-03T00:32:09.260Z

Reserved: 2022-06-28T00:00:00

Link: CVE-2022-2240

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-07-25T13:15:08.563

Modified: 2024-11-21T07:00:36.240

Link: CVE-2022-2240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses