The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection attacks against an admin exporting the data
                
            References
                    | Link | Resource | 
|---|---|
| https://wpscan.com/vulnerability/f169567d-c682-4abe-94df-a9d00be90edd | Exploit Third Party Advisory | 
| https://wpscan.com/vulnerability/f169567d-c682-4abe-94df-a9d00be90edd | Exploit Third Party Advisory | 
Configurations
                    History
                    21 Nov 2024, 07:01
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://wpscan.com/vulnerability/f169567d-c682-4abe-94df-a9d00be90edd - Exploit, Third Party Advisory | 
Information
                Published : 2022-09-16 09:15
Updated : 2024-11-21 07:01
NVD link : CVE-2022-2798
Mitre link : CVE-2022-2798
CVE.ORG link : CVE-2022-2798
JSON object : View
Products Affected
                wpaffiliatemanager
- affiliates_manager
CWE
                
                    
                        
                        CWE-1236
                        
            Improper Neutralization of Formula Elements in a CSV File
