CVE-2018-9035

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/04/2018
Last modified:
24/08/2020

Description

CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:contact-form-7-to-database-extension_project:contact-form-7-to-database-extension:*:*:*:*:*:*:*:* 2.10.32 (including)


References to Advisories, Solutions, and Tools