Vulnerability Description
The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Usabilitydynamics | Wp-Crm | <= 1.2.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/53c8190c-baef-4807-970b-f01ab440576aExploitThird Party Advisory
- https://wpscan.com/vulnerability/53c8190c-baef-4807-970b-f01ab440576aExploitThird Party Advisory
FAQ
What is CVE-2022-1202?
CVE-2022-1202 is a vulnerability with a CVSS score of 7.8 (HIGH). The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.
How severe is CVE-2022-1202?
CVE-2022-1202 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1202?
Check the references section above for vendor advisories and patch information. Affected products include: Usabilitydynamics Wp-Crm.