Vulnerabilities > CVE-2018-16308 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Ninjaforms Ninja Forms

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
ninjaforms
CWE-1236
exploit available

Summary

The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.

Vulnerable Configurations

Part Description Count
Application
Ninjaforms
221

Exploit-Db

idEDB-ID:45234