CVE-2020-22275
Summary
| CVE | CVE-2020-22275 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-04 17:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable. |
Risk And Classification
Problem Types: CWE-1236
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Easyregistrationforms | Easy Registration Forms | 2.0.6 | All | All | All |
| Application | Easyregistrationforms | Easy Registration Forms | 2.0.6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Download File UploadBoy.com Making Your File Sharing Easy! | MISC | uploadboy.com | Product, Third Party Advisory |
| Filebin | MISC | filebin.net | Exploit, Third Party Advisory |
| cert.ikiu.ac.ir/public-files/news/document/CVE-99/CVE-2020-22275.pdf | MISC | cert.ikiu.ac.ir | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.