CVE-2022-2240

Request a Quote <= 2.3.8 - CSV Injection

2022-06-28 00:00
Benachi

Strategic Overview

Status
Patched in 2.3.9
Affected Version
<= 2.3.8
CVSS
8.3High
Weakness type
CWE-1236 · Improper Neutralization of Formula Elements in a CSV File
CVE
CVE-2022-2240
View all Request a Quote – Quote Forms for Any WordPress Site vulnerabilities

At a glance

CVE-2022-2240 is a high-severity Improper Neutralization of Formula Elements in a CSV File vulnerability in the Request a Quote WordPress plugin, affecting versions <= 2.3.8. It carries a CVSS score of 8.3 (reachable over the network; low attack complexity). Exploitation requires no authentication. The issue is fixed in version 2.3.9; sites on affected versions should update now. Disclosed June 2022, reported by Benachi.

Vulnerability Overview

The Request a Quote WordPress plugin through 2.3.8 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it

Technical Analysis

The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user.

CWE-1236: Improper Neutralization of Formula Elements in a CSV File

The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Remediation

Update to version 2.3.9, or a newer patched version

How does WordSec protect against this?

The attempt arrives as an ordinary request to Request a Quote: WordSec's web application firewall inspects request payloads before WordPress loads them. None of that substitutes for the fix: Request a Quote 2.3.9 closes this, and updating the plugin is the step that ends it.

  • Firewall
  • Alerts

External References

Related records

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C