cleantalk
Vulnerabilities and Security Researches

Events Manager – Calendar, Bookings, Tickets, and more!, f4b5c879988cab9d450076a17bc8cfe77e92bff8

Published on
Feb 06, 2020
Research Description
Events Manager &#8211; Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.7.2 Events Manager < 5.9.7.2 & Events Manager Pro < 2.6.7.2 - Unauthenticated CSV Injection The Events Manager Pro, versions up to 2.6.7.2, and Events Manager, versions up to 5.9.7.2, plugins for WordPress are vulnerable to CSV Injection. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Affected versions
max 5.9.7.2.
Status
vulnerable