CVE-2022-2840
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
Affected (1)
Products: Zephyr One: Zephyr Project Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.2.5 |
References (4)
Source: contact@wpscan.com
ExploitThird Party AdvisoryVDB Entry
Source: contact@wpscan.com
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory
Timeline
No history available yet.