vendor:
Zephyr Project Manager
by:
Rizacan Tufan
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Zephyr Project Manager
Affected Version From: 3.2.42
Affected Version To: 3.2.42
Patch Exists: YES
Related CWE: CVE-2022-2840
CPE: 2.3:a:zephyr_one:zephyr_project_manager:3.2.42
Platforms Tested: Windows, Linux
2022
WordPress Plugin Zephyr Project Manager 3.2.42 – Multiple SQLi
Zephyr Project Manager is a plug-in that helps you manage and get things done effectively, all your projects and tasks. It has been determined that the data coming from the input field in most places throughout the application are used in the query without any sanitize and validation.
Mitigation:
Input validation and sanitization should be done for all user input.