The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
History

Tue, 03 Sep 2024 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Zephyr-one
Zephyr-one zephyr Project Manager
CPEs cpe:2.3:a:zephyr_project_manager_project:zephyr_project_manager:*:*:*:*:*:wordpress:*:* cpe:2.3:a:zephyr-one:zephyr_project_manager:*:*:*:*:*:wordpress:*:*
Vendors & Products Zephyr Project Manager Project
Zephyr Project Manager Project zephyr Project Manager
Zephyr-one
Zephyr-one zephyr Project Manager

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2022-09-19T00:00:00

Updated: 2024-08-03T00:52:59.448Z

Reserved: 2022-08-16T00:00:00

Link: CVE-2022-2840

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-09-19T14:15:11.000

Modified: 2024-09-03T13:24:12.813

Link: CVE-2022-2840

cve-icon Redhat

No data.