SB2020071007 - CSV Injection in Wise Chat plugin for WordPress
Published: July 10, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) CSV Injection (CVE-ID: N/A)
The vulnerability allows a remote attacker to inject arbitrary data into CSV files.
The vulnerability exists due to improper input validation when generating CSV files in chat messages. A remote attacker can create specially crafted CSV files and trick the victim into exporting the file with malicious content.
Remediation
Install update from vendor's website.
References
- https://wpvulndb.com/vulnerabilities/10299/
- https://fortiguard.com/zeroday/FG-VD-20-062
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fwise-chat%2Ftags%2F2.8.3%2Fsrc%2Fadmin%2FWiseChatChannelsTab.php&old=2282067&new_path=%2Fwise-chat%2Ftags%2F2.8.4%2Fsrc%2Fadmin%2FWiseChatChannelsTab.php&new=2334501