CVE-2019-16120: High severity tri event tickets vulnerability
Published Sep 8, 2019
·Updated
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.
Affected Software
2 affected components
Tri Event Tickets WordPress<4.10.7.2
Liquidweb Event Tickets Wordpress<4.10.7.2
Event History
Sep 8, 2019
CVE Published
via MITRE·10:48 PM
Data Sourced
via MITRE·10:48 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-16120?
CVE-2019-16120 is considered to have a medium severity due to its potential for CSV injection vulnerabilities.
2
How does CVE-2019-16120 affect users?
CVE-2019-16120 allows attackers to exploit the 'Export Attendees' feature to inject malicious CSV content.
3
How do I fix CVE-2019-16120?
To fix CVE-2019-16120, update the Event Tickets plugin to version 4.10.7.2 or later.
4
What versions of the Event Tickets plugin are affected by CVE-2019-16120?
CVE-2019-16120 affects all versions of the Event Tickets plugin prior to 4.10.7.2.
5
What action should I take if I cannot update the Event Tickets plugin for CVE-2019-16120?
If you cannot update, consider disabling the 'Export Attendees' feature until a fix can be applied.