PT-2019-15242 · Microsoft+1 · Office Excel+1
CVE-2019-17661
·
Publicado
2019-11-08
·
Atualizado
2024-10-15
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
codepress-admin-columns plugin version 3.4.6
Description
A CSV injection in the codepress-admin-columns plugin for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as their first or last name, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.
Recommendations
For version 3.4.6, consider updating to a newer version to mitigate the risk, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the ability to create users with names that contain formula code to minimize the risk of exploitation.
Exploit
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Office Excel
Codepress-Admin-Columns