Vulnerabilities > CVE-2018-16308 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Ninjaforms Ninja Forms

047910
CVSS 8.6 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
ninjaforms
CWE-1236
exploit available

Summary

The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.

Vulnerable Configurations

Part Description Count
Application
Ninjaforms
222

Exploit-Db

idEDB-ID:45234