CVE-2022-1539

CVE-2022-1539: Exports and Reports < 0.9.2 - Contributor+ CSV Injection

Vendor Unknown
Product Exports and Reports
Weakness CWE-1236
Published July 25, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.

Key dates

02Disclosure timeline

July 25, 2022 CVE published
August 3, 2024 Record updated