CVE-2022-2429 MEDIUM

CVE-2022-2429: Ultimate SMS Notifications for WooCommerce <= 1.4.1 - CSV Injection

Vendor Homescript
Product Ultimate SMS Notifications for WooCommerce
Weakness CWE-138
Published September 6, 2022
Last update January 31, 2025

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into billing information like their First Name that will embed into the exported CSV file triggered by an administrator and can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

Explanation of Vulnerability in Simple Terms

02Summary

Ultimate SMS Notifications for WooCommerce version 1.4.1 contains a vulnerability that allows an authenticated user with low privileges to perform actions affecting the site's confidentiality, integrity, and availability. The attack requires user interaction and can impact components beyond the plugin itself. Site administrators should update to a patched version when available.

What an attacker can do

03Attacker Capabilities

An authenticated user can trigger actions that may leak data, modify content, or disrupt service.

Potential impact on your site

04Site Impact

Your WooCommerce site's data, content, or availability could be compromised by a low-privilege user account.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege account and trick a user into clicking a malicious link or visiting a crafted page.

Key dates

06Disclosure timeline

September 6, 2022 CVE published
January 31, 2025 Record updated