The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-05-15 06:15
Updated : 2024-07-03 02:06
NVD link : CVE-2024-3748
Mitre link : CVE-2024-3748
CVE.ORG link : CVE-2024-3748
JSON object : View
Products Affected
No product.
CWE
No CWE.
