Lucene search

K
nvd[email protected]NVD:CVE-2022-2240
HistoryJul 25, 2022 - 1:15 p.m.

CVE-2022-2240

2022-07-2513:15:08
CWE-1236
web.nvd.nist.gov
2
wordpress
plugin
unauthenticated
csv injection
security vulnerability

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

66.3%

The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it

Affected configurations

Nvd
Node
emarketdesignrequest_a_quoteRange2.3.7wordpress
VendorProductVersionCPE
emarketdesignrequest_a_quote*cpe:2.3:a:emarketdesign:request_a_quote:*:*:*:*:*:wordpress:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

66.3%