CVE-2022-3604: Contact Form Entries < 1.3.0 - CSV Injection
Published Jan 16, 2024
·Updated
The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.
Affected Software
1 affected component
crmperks Database For Contact Form 7\, Wpforms\, Elementor Forms<1.3.0
Event History
Jan 16, 2024
CVE Published
via MITRE·03:52 PM
Data Sourced
via MITRE·03:52 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-3604?
CVE-2022-3604 has a medium severity rating due to potential CSV injection risks.
2
How do I fix CVE-2022-3604?
To fix CVE-2022-3604, update the Contact Form Entries WordPress plugin to version 1.3.0 or later.
3
What software is affected by CVE-2022-3604?
CVE-2022-3604 affects the Contact Form Entries WordPress plugin before version 1.3.0.
4
What type of vulnerability is CVE-2022-3604?
CVE-2022-3604 is classified as a CSV injection vulnerability.
5
Can CVE-2022-3604 lead to data breaches?
Yes, if exploited, CVE-2022-3604 could allow attackers to inject malicious content into CSV files, potentially leading to data breaches.