Mobile Events Manager < 1.4.8 - Admin+ CSV Injection
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.0%
exploitation probability
1.0%top 39% of all CVEs
observed exploitation
nono source reports it
The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.
Affected products
Unknown · Mobile Events Manager