Login by Auth0 <= 3.11.3 - CSV Injection

2020-04-01 00:00
Anonymous

Strategic Overview

Status
Patched in 4.0.0
Affected PluginLogin by Auth0
Affected Version<= 3.11.3
CVSS9.8Critical
CVECVE-2020-7947
View all Login by Auth0 vulnerabilities

Vulnerability Overview

An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting of the user data. This can lead to (at least) CSV injection if a crafted Excel document is uploaded.

Technical Analysis

REMEDIATION: Update to version 4.0.0, or a newer patched version --- IDENTIFIER: CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')) The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C