« Volver al listado

CVE-2022-1539

Estado: ModificadaAlta (8.8)—

The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-1539",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "contact@wpscan.com",
      "affectedData": [
        {
          "vendor": "Unknown",
          "product": "Exports and Reports",
          "versions": [
            {
              "status": "affected",
              "version": "0.9.2",
              "lessThan": "0.9.2",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-07-25T13:15:08.163",
  "references": [
    {
      "url": "https://wpscan.com/vulnerability/50f70927-9677-4ba4-a388-0a41ed356523",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "contact@wpscan.com"
    },
    {
      "url": "https://wpscan.com/vulnerability/50f70927-9677-4ba4-a388-0a41ed356523",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "contact@wpscan.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1236"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks."
    },
    {
      "lang": "es",
      "value": "El plugin Exports and Reports de WordPress versiones anteriores a 0.9.2, no sanea y comprueba los datos cuando genera el CSV a exportar, lo que podría conllevar a una inyección de CSV, mediante el uso de la función DDE de Microsoft Excel, o filtrar datos por medio de hipervínculos inyectados de forma maliciosa"
    }
  ],
  "lastModified": "2026-06-17T04:22:38.340",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:exports_and_reports_project:exports_and_reports:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93790A84-5A4E-4F54-8D52-B2C98B6720D5",
              "versionEndExcluding": "0.9.2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "contact@wpscan.com"
}