CVE-2020-36503: Connections Business Directory < 9.7 - Admin+ CSV Injection
Published Nov 1, 2021
·Updated
The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue
Affected Software
1 affected component
Connections-pro Connections Business Directory Wordpress>=0.7.3.2<=9.6
Remediation
Event History
Nov 1, 2021
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-36503?
CVE-2020-36503 has a critical severity level due to the potential for CSV injection.
2
How do I fix CVE-2020-36503?
To fix CVE-2020-36503, update the Connections Business Directory plugin to version 9.7 or later.
3
What type of attack does CVE-2020-36503 facilitate?
CVE-2020-36503 facilitates a CSV injection attack by allowing unvalidated user input in connections' fields.
4
Which versions of the Connections Business Directory plugin are affected by CVE-2020-36503?
CVE-2020-36503 affects Connections Business Directory versions before 9.7.
5
Can CVE-2020-36503 lead to data compromise?
Yes, CVE-2020-36503 can lead to data compromise through manipulation of CSV files.