The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file and not TablePress.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-01-09T00:00:00

Updated: 2024-06-04T17:12:02.333Z

Reserved: 2019-12-31T00:00:00


Link: CVE-2019-20180

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2020-01-09T21:15:11.933

Modified: 2024-06-04T19:16:59.167


Link: CVE-2019-20180

JSON object: View

cve-icon Redhat Information

No data.

CWE