Fiche vulnérabilité
CVE-2022-1539 : faille élevée exports and reports project exports… (CVSS 8.8)
Description
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 25 juil. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- exports and reports project exports and reports