'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2020-9372: Wordpress Plugin Appointment Booking Calendar CSV Injection Vulnerability.
Severity:mid
CVE ID:CVE-2020-9372
| Descripiton:
|
WordPress is a free and open-source content management system (CMS) based on PHP and MySQL. WordPress is installed on a Web server that is either a part of an Internet hosting service or a network host in its own right. The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection. This rule supports to defend the A6: Vulnerable and Outdated Components and A3: Injection of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.