Description


The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.

References



https://www.exploit-db.com/exploits/44559/

ExploitThird Party AdvisoryVDB Entry

Weaknesses



CWE-1236

CVSS impact metrics


CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.8 · High

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2018-04-27T16:29:00.987

7 years ago

Last modified

2020-08-24T17:37:01.140

4 years ago