Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable.
References
Link Resource
http://uploadboy.com/ty0715vdcii6/886/mp4 Product Third Party Advisory
https://cert.ikiu.ac.ir/public-files/news/document/CVE-99/CVE-2020-22275.pdf Exploit Third Party Advisory
https://filebin.net/30ceikgukh268yyj Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-11-04T16:59:58

Updated: 2020-11-04T16:59:58

Reserved: 2020-08-13T00:00:00


Link: CVE-2020-22275

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-11-04T17:15:12.910

Modified: 2021-07-21T11:39:23.747


Link: CVE-2020-22275

JSON object: View

cve-icon Redhat Information

No data.

CWE