ZeroHour

CVE-2022-2798

PoC
CVSS 3.1
8.0 high
EPSS
1%p66
Published
()
Modified
Description

The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection attacks against an admin exporting the data

Vendors
wpaffiliatemanager
Products
affiliates manager
Ecosystems
WordPress
Weakness
CWE-1236
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.