CVE-2022-3634: Contact Form 7 Database Addon < 1.2.6.5 - CSV Injection
Published Nov 21, 2022
·Updated
The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection
Affected Software
1 affected component
Ciphercoin Contact Form 7 Database Addon Wordpress<1.2.6.5
Event History
Nov 21, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-3634.
2
What is the severity of CVE-2022-3634?
The severity of CVE-2022-3634 is critical (9.8).
3
What is the affected software?
The affected software is Ciphercoin Contact Form 7 Database Addon plugin version up to 1.2.6.5 for WordPress.
4
What is the impact of this vulnerability?
The impact of this vulnerability is CSV injection, which could lead to malicious code execution or unauthorized access to sensitive information.
5
How can I fix CVE-2022-3634?
To fix CVE-2022-3634, update the Ciphercoin Contact Form 7 Database Addon plugin to version 1.2.6.5 or higher.