9.8
CVSSv3

CVE-2022-2840

Published: 19/09/2022 Updated: 03/12/2022
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The Zephyr Project Manager WordPress plugin prior to 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zephyr project manager project zephyr project manager

Exploits

# Exploit Title: Wordpress Plugin Zephyr Project Manager 3242 - Multiple SQLi # Date: 14-08-2022 # Exploit Author: Rizacan Tufan # Blog Post: rizaxblog/blog/wordpress-plugin-zephyr-project-manager-multiple-sqli-authenticated # Software Link: wordpressorg/plugins/zephyr-project-manager/ # Vendor Homepage: zephyr-onecom/ ...
WordPress Zephyr Project Manager plugin version 3242 suffers from a remote SQL injection vulnerability ...