CVE-2019-11872

The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a pop-up window. Successful exploitation grants an attacker with a right to execute malicious code on the administrator's computer through Excel functions as the plugin does not sanitize the user's input and allows insertion of any text.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:incsub:hustle:*:*:*:*:*:wordpress:*:*

Information

Published : 2019-05-29 12:29

Updated : 2023-02-24 11:33


NVD link : CVE-2019-11872

Mitre link : CVE-2019-11872


JSON object : View

CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File

Advertisement

dedicated server usa

Products Affected

incsub

  • hustle