Events Manager – Calendar, Bookings, Tickets, and more!, f4b5c879988cab9d450076a17bc8cfe77e92bff8
- CVE, Research URL
- Published on
- Feb 06, 2020
- Research Description
- Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.7.2 Events Manager < 5.9.7.2 & Events Manager Pro < 2.6.7.2 - Unauthenticated CSV Injection The Events Manager Pro, versions up to 2.6.7.2, and Events Manager, versions up to 5.9.7.2, plugins for WordPress are vulnerable to CSV Injection. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
- Affected versions
-
max 5.9.7.2.
- Status
-
vulnerable