// For flags

CVE-2020-22275

Easy Registration Forms <= 2.0.6 - CSV Injection

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable.

Easy Registration Forms (ER Forms) en el Plugin de Wordpress versión 2.0.6, permite a un atacante enviar una entrada con comandos CSV maliciosos.&#xa0;Después de eso, cuando el administrador del sistema genera una salida CSV desde la información de los formularios, no presenta una comprobación de estas entradas y los códigos son ejecutables

*Credits: Mohamad Pishdar
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-08-13 CVE Reserved
  • 2020-11-04 CVE Published
  • 2024-07-22 EPSS Updated
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
  • CWE-1236: Improper Neutralization of Formula Elements in a CSV File
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Easyregistrationforms
Search vendor "Easyregistrationforms"
Easy Registration Forms
Search vendor "Easyregistrationforms" for product "Easy Registration Forms"
2.0.6
Search vendor "Easyregistrationforms" for product "Easy Registration Forms" and version "2.0.6"
wordpress
Affected