CVE-2024-3748

The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user
Configurations

No configuration.

History

No history.

Information

Published : 2024-05-15 06:15

Updated : 2024-07-03 02:06


NVD link : CVE-2024-3748

Mitre link : CVE-2024-3748

CVE.ORG link : CVE-2024-3748


JSON object : View

Products Affected

No product.

CWE

No CWE.