WordPress amr users Plugin <= 4.59.4 is vulnerable to CSV Injection
CVE-2022-45348
8.8HIGH
What is CVE-2022-45348?
A vulnerability exists in the amr users product developed by anmari, where improper neutralization of formula elements in CSV files can lead to CSV injection attacks. This issue affects versions from n/a through 4.59.4, allowing attackers to execute arbitrary commands by crafting malicious CSV contents. It is crucial for users to apply security measures and updates to mitigate potential exploitation risks.
Affected Version(s)
amr users <= 4.59.4