ZeroHour

CVE-2020-9372

PoC ×2
CVSS 3.1
7.8 high
EPSS
9%p95
Published
()
Modified
Description

The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.

Vendors
codepeople
Products
appointment booking calendar
Ecosystems
WordPress
Weakness
CWE-1236
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.