CVE-2022-1194
Mobile Events Manager < 1.4.8 - Admin+ CSV Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.
El plugin Mobile Events Manager de WordPress versiones anteriores a 1.4.8 no escapa apropiadamente del campo Enquiry source cuando son exportados eventos, o del campo Paid for cuando son exportados transacciones como CSV, conllevando a una vulnerabilidad de inyección CSV
The Mobile Events Manager plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.7. This allows administrator level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-31 CVE Reserved
- 2022-08-17 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-1236: Improper Neutralization of Formula Elements in a CSV File
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/62be0991-f095-43cf-a167-3daaed254594 | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mobileeventsmanager Search vendor "Mobileeventsmanager" | Mobile Events Manager Search vendor "Mobileeventsmanager" for product "Mobile Events Manager" | < 1.4.8 Search vendor "Mobileeventsmanager" for product "Mobile Events Manager" and version " < 1.4.8" | wordpress |
Affected
|