CVE-2022-2798
Summary
| CVE | CVE-2022-2798 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-16 09:15:00 UTC |
| Updated | 2022-09-20 14:28:00 UTC |
| Description | The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection attacks against an admin exporting the data |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Affiliates Manager < 2.9.14 - Affiliate CSV Injection WordPress Security Vulnerability |
MISC |
wpscan.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: nhatnam
Legacy QID Mappings
- 150573 WordPress Affiliates Manager Plugin: Multiple Vulnerabilities (CVE-2022-2798,CVE-2022-2799)