PT-2020-19866 · Auth0 · Login By Auth0 Plugin For Wordpress
Muhamad Visat
·
Published
2020-04-01
·
Updated
2021-07-21
·
CVE-2020-7947
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Login by Auth0 plugin for WordPress versions prior to 4.0.0
Description
The issue arises from the plugin's failure to sanitize and validate data from various sources before exporting user data. This oversight can lead to CSV injection attacks if a maliciously crafted Excel document is uploaded.
Recommendations
For versions prior to 4.0.0, update to version 4.0.0 or later to resolve the issue. As a temporary workaround, consider restricting the upload of Excel documents or implementing additional validation and sanitization of user data before export.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Login By Auth0 Plugin For Wordpress