CVE-2020-22275
Estado: ModificadaAlta (8.8)—
Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.17%
- Percentil entre todas las CVEs puntuadas: 82
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-1236
Referencias
- http://uploadboy.com/ty0715vdcii6/886/mp4
- https://cert.ikiu.ac.ir/public-files/news/document/CVE-99/CVE-2020-22275.pdf
- https://filebin.net/30ceikgukh268yyj
- http://uploadboy.com/ty0715vdcii6/886/mp4
- https://cert.ikiu.ac.ir/public-files/news/document/CVE-99/CVE-2020-22275.pdf
- https://filebin.net/30ceikgukh268yyj
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-22275",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2020-11-04T17:15:12.910",
"references": [
{
"url": "http://uploadboy.com/ty0715vdcii6/886/mp4",
"tags": [
"Product",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://cert.ikiu.ac.ir/public-files/news/document/CVE-99/CVE-2020-22275.pdf",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://filebin.net/30ceikgukh268yyj",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://uploadboy.com/ty0715vdcii6/886/mp4",
"tags": [
"Product",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://cert.ikiu.ac.ir/public-files/news/document/CVE-99/CVE-2020-22275.pdf",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://filebin.net/30ceikgukh268yyj",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-1236"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable."
},
{
"lang": "es",
"value": "Easy Registration Forms (ER Forms) en el Plugin de Wordpress versión 2.0.6, permite a un atacante enviar una entrada con comandos CSV maliciosos. Después de eso, cuando el administrador del sistema genera una salida CSV desde la información de los formularios, no presenta una comprobación de estas entradas y los códigos son ejecutables"
}
],
"lastModified": "2026-06-17T03:04:12.940",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:easyregistrationforms:easy_registration_forms:2.0.6:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "155A5619-ABFC-4B3D-A14A-17468DEB9D05"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}