CVE-2024-3748
MEDIUMDescription
The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user
Is your site exposed to CVE-2024-3748?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| smartypantsplugins | sp_project_\&_document_manager |
References
Frequently Asked Questions
What is CVE-2024-3748? +
How severe is CVE-2024-3748? +
What products are affected by CVE-2024-3748? +
How do I check if I'm vulnerable to CVE-2024-3748? +
Related Vulnerabilities
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This …
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in smartypants SP Project & Document Manager.This issue …
The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user …