CVE-2022-3604

The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:crmperks:database_for_contact_form_7\,_wpforms\,_elementor_forms:*:*:*:*:*:*:*:*

History

24 Jan 2024, 16:58

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-1236
References () https://wpscan.com/vulnerability/300ebfcd-c500-464e-b919-acfeb72593de/ - () https://wpscan.com/vulnerability/300ebfcd-c500-464e-b919-acfeb72593de/ - Exploit, Third Party Advisory
Summary
  • (es) El complemento de WordPress Contact Form Entries anterior a 1.3.0 no valida los datos cuando se generan en un archivo CSV, lo que podría provocar una inyección de CSV.
First Time Crmperks
Crmperks database For Contact Form 7\, Wpforms\, Elementor Forms
CPE cpe:2.3:a:crmperks:database_for_contact_form_7\,_wpforms\,_elementor_forms:*:*:*:*:*:*:*:*

16 Jan 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-16 16:15

Updated : 2024-01-24 16:58


NVD link : CVE-2022-3604

Mitre link : CVE-2022-3604

CVE.ORG link : CVE-2022-3604


JSON object : View

Products Affected

crmperks

  • database_for_contact_form_7\,_wpforms\,_elementor_forms
CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File