Description
Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.
References
https://github.com/RashidKhanPathan/CVE-2022-44830
ExploitThird Party Advisory
https://github.com/RashidKhanPathan/CVE-2022-44830
ExploitThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 · High
Information
Source identifier
Vulnerability status
Modified
Published
2022-11-21T17:15:25.317Z
3 years agoLast modified
2025-04-29T14:15:28.697Z
10 months ago