cleantalk
Vulnerabilities and Security Researches

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress, 4d4dec44bed3364eeef20d4c24615d186947040c

Published on
Sep 30, 2015
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.28 Ninja Forms Contact Form <= 2.9.27 - CSV Injection The Ninja Forms Contact Form plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.9.27 via the export() function. This allows authenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Affected versions
max 2.9.28.
Status
vulnerable