What the vulnerability does
01Description
Improper Neutralization of Formula Elements in a CSV File vulnerability in GiveWP.This issue affects GiveWP: from n/a through 2.25.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
What the vulnerability does
Improper Neutralization of Formula Elements in a CSV File vulnerability in GiveWP.This issue affects GiveWP: from n/a through 2.25.1.
Explanation of Vulnerability in Simple Terms
GiveWP versions up to 2.25.1 contain a cross-site scripting vulnerability that allows an attacker to inject malicious scripts through user interaction. The vulnerability requires the victim to visit a specially crafted link or page. An attacker can read or modify limited data, but cannot disrupt site availability. Update to a version newer than 2.25.1.
What an attacker can do
Inject malicious scripts that execute in a victim's browser and read or modify limited data.
Potential impact on your site
Site visitors may have their session data read or modified if they interact with attacker-controlled content.
Conditions required to exploit
Victim must click a malicious link or visit an attacker-controlled page; no authentication required.
Key dates
External resources
Related vulnerabilities