Vulnerabilities > CVE-2022-3393 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Bestwebsoft Post to CSV
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection