2024-12-15 03:03:56 +00:00

90 lines
2.6 KiB
JSON

{
"id": "CVE-2022-1194",
"sourceIdentifier": "contact@wpscan.com",
"published": "2022-09-16T09:15:10.177",
"lastModified": "2024-11-21T06:40:13.807",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability."
},
{
"lang": "es",
"value": "El plugin Mobile Events Manager de WordPress versiones anteriores a 1.4.8 no escapa apropiadamente del campo Enquiry source cuando son exportados eventos, o del campo Paid for cuando son exportados transacciones como CSV, conllevando a una vulnerabilidad de inyecci\u00f3n CSV"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "contact@wpscan.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-1236"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mobileeventsmanager:mobile_events_manager:*:*:*:*:*:wordpress:*:*",
"versionEndExcluding": "1.4.8",
"matchCriteriaId": "F8C5F197-F5D6-4433-8B75-0224B585ABDB"
}
]
}
]
}
],
"references": [
{
"url": "https://wpscan.com/vulnerability/62be0991-f095-43cf-a167-3daaed254594",
"source": "contact@wpscan.com",
"tags": [
"Exploit",
"Third Party Advisory"
]
},
{
"url": "https://wpscan.com/vulnerability/62be0991-f095-43cf-a167-3daaed254594",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Third Party Advisory"
]
}
]
}