CVE-2020-9372
Appointment Booking Calendar <= 1.3.34 - CSV Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.
El plugin Appointment Booking Calendar versiones anteriores a 1.3.35 para WordPress, permite que la entrada de usuario sea cualquier fórmula (en campos tales como Description o Name) en cualquier formulario de reserva, que luego podría ser exportado por medio de la pestaña Bookings list en /wp-admin/admin.php?page=cpabc_appointments.php. El atacante podría lograr la ejecución remota de código por medio de una inyección CSV.
WordPress Appointment Booking Calendar plugin version 1.3.34 suffers from a CSV injection vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-02-24 CVE Reserved
- 2020-03-04 CVE Published
- 2020-03-12 First Exploit
- 2023-11-20 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CWE-1236: Improper Neutralization of Formula Elements in a CSV File
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://wordpress.org/plugins/appointment-booking-calendar/#developers | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Codepeople Search vendor "Codepeople" | Appointment Booking Calendar Search vendor "Codepeople" for product "Appointment Booking Calendar" | < 1.3.35 Search vendor "Codepeople" for product "Appointment Booking Calendar" and version " < 1.3.35" | wordpress |
Affected
|