This is Robert from Patchstack here to help if I can.
First, I would like to apologize to the users receiving a concerning report on a Friday morning of all times. I updated the finding regarding this bug in our database to help clarify the concerns, reducing the risk rating down to a Low. Other changes in how this was communicated could have helped too, but they’re out of my control right now.
What is CSV Injection? These have always been troubling vulnerabilities to report and communicate. There is no risk to the website itself, but there maybe a risk to users who download CSV files exported form the website. In a strange twist, it’s the web application that applies the patch to address this concern.
If you do not export CSV files using this plugin then this report is not applicable to you. And if you do, just be careful with the export file, by “careful” I mean: Do not disable multiple security features or ignore warnings when opening the file.
For @eskapism:
Because of the complex requirements of the attack vector, we recently stopped accepting CSV injection reports from the Patchstack Alliance bug bounty program. Why is it being published now? We accepted this report before therecent decision to stop accepting CSV Injection reports. We attempted to reach out to you multiple times in the last few months, but never heard back. It would really help us if you could share a security point of contact (but we should discuss this elsewhere)
We will be re-evaluating if we keep this report active at all, but the decision may take time and will take more time to propagate to the WordPress toolkit or other vendors. For now I have reduced the severity on our end, and can help answer any other questions or concerns you may have.
If you by chance wish to write a patch, I wrote about the concerns of CSV Injection, and how you can patch it easily here. https://patchstack.com/articles/patchstack-weekly-what-is-csv-injection/ — You should not feel this is an emergency thing to patch, but this would have been easier and less stressful had we been able to get in contact with you sooner.
-
This reply was modified 1 year, 9 months ago by rawrly.