ZeroHour

CVE-2020-22275

PoC ×2
CVSS 3.1
8.8 high
EPSS
2%p81
Published
()
Modified
Description

Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable.

Vendors
easyregistrationforms
Products
easy registration forms
Ecosystems
WordPress
Weakness
CWE-1236
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.