cleantalk
Vulnerabilities and Security Researches

Zephyr Project Manager, CVE-2022-2840

CVE, Research URL

CVE-2022-2840

Published on
Sep 19, 2022
Research Description
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
Affected versions
Min -, max 3.2.5.
Status
vulnerable