CVE-2022-2240
Request a Quote <= 2.3.7 - CSV Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it
El plugin Request a Quote de WordPress versiones hasta 2.3.7, no comprueba los archivos CSV subidos, lo que permite a usuarios no autenticados adjuntar un archivo CSV malicioso a un presupuesto, lo que podría conllevar a una inyección CSV una vez que un administrador lo descargue y lo abra
The Request a Quote WordPress plugin through 2.3.8 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-06-28 CVE Reserved
- 2022-06-28 CVE Published
- 2024-02-15 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-1236: Improper Neutralization of Formula Elements in a CSV File
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/6a3a573e-f9f2-45ec-9156-332cc551fc7e | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Emarketdesign Search vendor "Emarketdesign" | Request A Quote Search vendor "Emarketdesign" for product "Request A Quote" | <= 2.3.7 Search vendor "Emarketdesign" for product "Request A Quote" and version " <= 2.3.7" | wordpress |
Affected
|