NA

CVE-2022-1539

Published: 25/07/2022 Updated: 29/07/2022
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Exports and Reports WordPress plugin prior to 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

exports and reports project exports and reports