Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/143cdaff-c536-4ff9-8d64-c617511ddd48 | Third Party Advisory |
Configurations
Information
Published : 2021-03-18 08:15
Updated : 2022-11-14 07:19
NVD link : CVE-2021-24144
Mitre link : CVE-2021-24144
JSON object : View
CWE
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
Products Affected
ciphercoin
- contact_form_7_database_addon