Skip to main content
HIGH

CVE-2019-17661

CVSS v3

8.8

HIGH

EPSS Score

1.4 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as his first or last name, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.

Technical details

Published
2019-11-08

Frequently asked questions

What is CVE-2019-17661?

A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as his first or last name, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.

Is CVE-2019-17661 actively exploited?

Active exploitation of CVE-2019-17661 has not been confirmed. The EPSS score is 1.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-17661?

CVE-2019-17661 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2019-17661 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key