CVE-2022-3558
Import and export users and customers < 1.20.5 - Subscriber+ CSV Injection
Severity Score
8.0
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.
El complemento de WordPress para importar y exportar usuarios y clientes anteriores a 1.20.5 no escapa correctamente los datos al exportarlos a través de archivos CSV.
The Import and export users and customers plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.20.4. This allows subscriber-level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
*Credits:
Adel Bouaricha
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-10-17 CVE Reserved
- 2022-10-17 CVE Published
- 2024-05-30 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-1236: Improper Neutralization of Formula Elements in a CSV File
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/e3d72e04-9cdf-4b7d-953e-876e26abdfc6 | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://plugins.trac.wordpress.org/changeset?new=2798139%40import-users-from-csv-with-meta&old=2785785%40import-users-from-csv-with-meta | 2022-11-10 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Codection Search vendor "Codection" | Import And Export Users And Customers Search vendor "Codection" for product "Import And Export Users And Customers" | < 1.20.5 Search vendor "Codection" for product "Import And Export Users And Customers" and version " < 1.20.5" | wordpress |
Affected
|