WordPress Plugin Vulnerabilities

SP Project & Document Manager <= 4.71 - Data Update via IDOR

Description

The plugin is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user

Proof of Concept

Affects Plugins

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
fewwords
Submitter
fewwords
Verified
Yes

Timeline

Publicly Published
2024-04-24 (about 1 year ago)
Added
2024-04-24 (about 1 year ago)
Last Updated
2024-04-24 (about 1 year ago)

Other