PT-2022-13707 · WordPress · Mobile Events Manager

Varun Thorat

·

Published

2022-09-16

·

Updated

2022-09-20

·

CVE-2022-1194

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mobile Events Manager WordPress plugin versions prior to 1.4.8
Description The issue arises from the improper escaping of the Enquiry source field when exporting events and the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.
Recommendations For versions prior to 1.4.8, update to version 1.4.8 or later to resolve the issue. As a temporary workaround, consider avoiding the export of events and transactions as CSV until the update is applied.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1194

Affected Products

Mobile Events Manager