SP Project & Document Manager < 4.58 - Sensitive File Disclosure
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.9%
exploitation probability
0.9%top 43% of all CVEs
observed exploitation
nono source reports it
The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.
Affected products
Unknown · SP Project & Document Manager