Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown
CVE-2024-37224
Disclosure Date: July 09, 2024 (last updated July 22, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager: from n/a through 4.71.
0
Attacker Value
Unknown
CVE-2024-1693
Disclosure Date: May 14, 2024 (last updated January 05, 2025)
The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cdm_save_category AJAX action in all versions up to, and including, 4.70. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary folder name that do not belong to them.
0
Attacker Value
Unknown
CVE-2024-33923
Disclosure Date: May 03, 2024 (last updated May 03, 2024)
Missing Authorization vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.69.
0
Attacker Value
Unknown
CVE-2024-32551
Disclosure Date: April 18, 2024 (last updated April 18, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.71.
0
Attacker Value
Unknown
CVE-2024-24868
Disclosure Date: February 28, 2024 (last updated February 29, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager: from n/a through 4.69.
0
Attacker Value
Unknown
CVE-2023-36677
Disclosure Date: November 03, 2023 (last updated November 10, 2023)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager allows SQL Injection.This issue affects SP Project & Document Manager: from n/a through 4.67.
0
Attacker Value
Unknown
CVE-2023-36530
Disclosure Date: August 10, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smartypants SP Project & Document Manager plugin <= 4.67 versions.
0
Attacker Value
Unknown
CVE-2023-3063
Disclosure Date: June 30, 2023 (last updated November 09, 2023)
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with subscriber privileges or above, to change user passwords and potentially take over administrator accounts.
0
Attacker Value
Unknown
CVE-2022-34857
Disclosure Date: August 10, 2022 (last updated October 08, 2023)
Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPress
0
Attacker Value
Unknown
CVE-2022-1551
Disclosure Date: July 25, 2022 (last updated October 07, 2023)
The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.
0