CVE-2021-24144: Contact Form 7 Database Addon < 1.2.5.6 - CSV Injection
Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24144?
CVE-2021-24144 is a vulnerability in the Contact Form 7 Database Addon plugin versions before 1.2.5.6 that allows remote attackers to inject arbitrary formulas into CSV files.
How severe is CVE-2021-24144?
CVE-2021-24144 has a severity score of 7.8, which is considered high.
What software versions are affected by CVE-2021-24144?
Versions of the Contact Form 7 Database Addon plugin before 1.2.5.6 are affected by CVE-2021-24144.
How can I fix CVE-2021-24144?
To fix CVE-2021-24144, update the Contact Form 7 Database Addon plugin to version 1.2.5.6 or later.
Where can I find more information about CVE-2021-24144?
You can find more information about CVE-2021-24144 at the following reference: https://wpscan.com/vulnerability/143cdaff-c536-4ff9-8d64-c617511ddd48