Vulnerabilities > CVE-2018-11525 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Algolplus Advanced Order Export for Woocommerce

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
algolplus
CWE-1236
exploit available

Summary

The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.

Vulnerable Configurations

Part Description Count
Application
Algolplus
42

Exploit-Db

descriptionWordpress Plugin Advanced Order Export For WooCommerce < 1.5.4 - CSV Injection. CVE-2018-11525. Webapps exploit for PHP platform
fileexploits/php/webapps/44931.txt
idEDB-ID:44931
last seen2018-06-25
modified2018-06-25
platformphp
port80
published2018-06-25
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/44931/
titleWordpress Plugin Advanced Order Export For WooCommerce < 1.5.4 - CSV Injection
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/148297/wpaoew-csvinject.txt
idPACKETSTORM:148297
last seen2018-06-26
published2018-06-25
reporterBhushan B. Patil
sourcehttps://packetstormsecurity.com/files/148297/WordPress-Advanced-Order-Export-For-WooCommerce-CSV-Injection.html
titleWordPress Advanced Order Export For WooCommerce CSV Injection