JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
References
Link | Resource |
---|---|
https://cert.ikiu.ac.ir/public-files/news/document/CVE-99/CVE-2020-22274.pdf | Third Party Advisory |
https://gofile.io/?c=LsAOtL | Broken Link |
http://uploadboy.me/iypl38958pon/JomSocial.mp4.html | Third Party Advisory |
Configurations
Information
Published : 2020-11-04 10:15
Updated : 2020-11-12 08:17
NVD link : CVE-2020-22274
Mitre link : CVE-2020-22274
JSON object : View
CWE
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
Products Affected
jomsocial
- jomsocial