T
he Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
References
| Link | Resource |
|---|---|
| https://wordpress.org/plugins/search-meter/#developers | Product Third Party Advisory |
| https://www.exploit-db.com/exploits/48197 | Third Party Advisory VDB Entry |
| https://wordpress.org/plugins/search-meter/#developers | Product Third Party Advisory |
| https://www.exploit-db.com/exploits/48197 | Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 04:58
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://wordpress.org/plugins/search-meter/#developers - Product, Third Party Advisory | |
| References | () https://www.exploit-db.com/exploits/48197 - Third Party Advisory, VDB Entry |
Information
Published : 2020-04-05 00:15
Updated : 2024-11-21 04:58
NVD link : CVE-2020-11548
Mitre link : CVE-2020-11548
CVE.ORG link : CVE-2020-11548
JSON object : View
Products Affected
CWE
CWE-1236
Improper Neutralization of Formula Elements in a CSV File