CSV Import and Export version 1.1.0 suffers from cross site scripting and remote SQL injection vulnerabilities. Continue reading...