Vulnerabilities > CVE-2018-9035 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Contact-Form-7-To-Database-Extension Project Contact-Form-7-To-Database-Extension 2.10.30/2.10.31/2.10.32

047910
CVSS 9.6 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
contact-form-7-to-database-extension-project
CWE-1236
critical
exploit available

Summary

CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form.

Exploit-Db

descriptionWordPress Plugin Contact Form 7 to Database Extension 2.10.32 - CSV Injection. CVE-2018-9035. Webapps exploit for PHP platform
fileexploits/php/webapps/44367.txt
idEDB-ID:44367
last seen2018-05-24
modified2018-03-30
platformphp
port80
published2018-03-30
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/44367/
titleWordPress Plugin Contact Form 7 to Database Extension 2.10.32 - CSV Injection
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/146988/wpcf7de21032-csvinject.txt
idPACKETSTORM:146988
last seen2018-04-03
published2018-03-31
reporterStefan Broeder
sourcehttps://packetstormsecurity.com/files/146988/WordPress-Contact-Form-7-To-Database-Extension-2.10.32-CSV-Injection.html
titleWordPress Contact Form 7 To Database Extension 2.10.32 CSV Injection