The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
References
Link | Resource |
---|---|
https://wordpress.org/plugins/form-maker/#developers | Third Party Advisory |
https://www.exploit-db.com/exploits/44559/ | Exploit Third Party Advisory VDB Entry |
https://wordpress.org/plugins/form-maker/#developers | Third Party Advisory |
https://www.exploit-db.com/exploits/44559/ | Exploit Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 03:41
Type | Values Removed | Values Added |
---|---|---|
References | () https://wordpress.org/plugins/form-maker/#developers - Third Party Advisory | |
References | () https://www.exploit-db.com/exploits/44559/ - Exploit, Third Party Advisory, VDB Entry |
Information
Published : 2018-04-27 16:29
Updated : 2024-11-21 03:41
NVD link : CVE-2018-10504
Mitre link : CVE-2018-10504
CVE.ORG link : CVE-2018-10504
JSON object : View
Products Affected
web-dorado
- form_maker
CWE
CWE-1236
Improper Neutralization of Formula Elements in a CSV File