ZeroHour

CVE-2021-24144

CVSS 3.1
7.8 high
EPSS
1%p67
Published
()
Modified
Description

Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.

Vendors
ciphercoin
Products
contact form 7 database addon
Weakness
CWE-74, CWE-1236
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news