packetstormsecurity.com
http://packetstormsecurity.com/files/168652/WordPress-Zephyr-Project-Manager-3.2.42-SQL-Injection.html CVE-2022-2840
CRITICAL
Zephyr Project Manager < 3.2.5 - Multiple Unauthenticated SQLi
Record summary
CVE-2022-2840 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Zephyr Project Manager | CVE List | 3.2.5 to < 3.2.5 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordpress Plugin Zephyr Project Manager 3.2.42 - Multiple SQLiExploitDB exploitby Rizacan TufanNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-2840 wpscan.com
https://wpscan.com/vulnerability/13d8be88-c3b7-4d6e-9792-c98b801ba53c