Vulnerabilities > CVE-2022-3600 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Sandhillsdev Easy Digital Downloads

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
sandhillsdev
CWE-1236
critical

Summary

The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.

Vulnerable Configurations

Part Description Count
Application
Sandhillsdev
271