cve/2022/CVE-2022-1539.md

18 lines
865 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2022-1539](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1539)
![](https://img.shields.io/static/v1?label=Product&message=Exports%20and%20Reports&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=0.9.2%3C%200.9.2%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-1236%20Improper%20Neutralization%20of%20Formula%20Elements%20in%20a%20CSV%20File&color=brighgreen)
### Description
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.
### POC
#### Reference
- https://wpscan.com/vulnerability/50f70927-9677-4ba4-a388-0a41ed356523
#### Github
No PoCs found on GitHub currently.