CVE-2022-44830

HIGH

Sourcecodester Event Registration App v1.0 - Code Injection

Title source: llm
STIX 2.1

Description

Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.

Exploits (1)

nomisec WRITEUP 1 stars
by RashidKhanPathan · poc
https://github.com/RashidKhanPathan/CVE-2022-44830

Scores

CVSS v3 7.8
EPSS 0.0653
EPSS Percentile 91.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-1236
Status published
Products (1)
event_registration_application_project/event_registration_application 1.0
Published Nov 21, 2022
Tracked Since Feb 18, 2026