Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown
CVE-2024-37224
Disclosure Date: July 09, 2024 (last updated July 22, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager: from n/a through 4.71.
0
Attacker Value
Unknown
CVE-2024-3749
Disclosure Date: May 15, 2024 (last updated May 15, 2024)
The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user
0
Attacker Value
Unknown
CVE-2024-3748
Disclosure Date: May 15, 2024 (last updated May 15, 2024)
The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user
0
Attacker Value
Unknown
CVE-2024-1693
Disclosure Date: May 14, 2024 (last updated January 05, 2025)
The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cdm_save_category AJAX action in all versions up to, and including, 4.70. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary folder name that do not belong to them.
0
Attacker Value
Unknown
CVE-2024-33923
Disclosure Date: May 03, 2024 (last updated May 03, 2024)
Missing Authorization vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.69.
0
Attacker Value
Unknown
CVE-2024-32551
Disclosure Date: April 18, 2024 (last updated April 18, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.71.
0
Attacker Value
Unknown
CVE-2024-24868
Disclosure Date: February 28, 2024 (last updated February 29, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager: from n/a through 4.69.
0
Attacker Value
Unknown
CVE-2023-36677
Disclosure Date: November 03, 2023 (last updated November 10, 2023)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager allows SQL Injection.This issue affects SP Project & Document Manager: from n/a through 4.67.
0
Attacker Value
Unknown
CVE-2023-36530
Disclosure Date: August 10, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smartypants SP Project & Document Manager plugin <= 4.67 versions.
0
Attacker Value
Unknown
CVE-2023-3063
Disclosure Date: June 30, 2023 (last updated November 09, 2023)
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with subscriber privileges or above, to change user passwords and potentially take over administrator accounts.
0