← Zuruck zu CVEs
CVE-2020-7947
CRITICAL9.8
Beschreibung
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting of the user data. This can lead to (at least) CSV injection if a crafted Excel document is uploaded.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht4/1/2020
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
auth0:login_by_auth0
Schwachen (CWE)
CWE-1236
Referenzen
https://auth0.com/docs/cms/wordpress(cve@mitre.org)
https://auth0.com/docs/security/bulletins/2020-03-31_wpauth0(cve@mitre.org)
https://wordpress.org/plugins/auth0/#developers(cve@mitre.org)
https://auth0.com/docs/cms/wordpress(af854a3a-2127-422b-91ae-364da2661108)
https://auth0.com/docs/security/bulletins/2020-03-31_wpauth0(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/auth0/wp-auth0/security/advisories/GHSA-59vf-cgfw-6h6v(af854a3a-2127-422b-91ae-364da2661108)
https://wordpress.org/plugins/auth0/#developers(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.