Zephyr Project Manager < 3.2.5 - Multiple Unauthenticated SQLi
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 10%
from disclosure to weapon17 days
Published on NVDSep 19
1st PoC+17d
exploitation probability
10%top 5% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
Affected products
Unknown · Zephyr Project Managerpublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/51024cve_referencepacketstormsecurity.com/files/168652/WordPress-Zephyr-Project-Manager-3.2.42-SQL-Injection.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.