SP Project & Document Manager <= 4.57 - Sensitive File Disclosure
2022-06-28 00:00
Viktor MarkopoulosStrategic Overview
StatusPatched in 4.58
Affected PluginSP Project & Document Manager
Affected Version
<= 4.57CVSS5.3Medium
CVE
CVE-2022-1551Vulnerability Overview
The SP Project & Document Manager WordPress plugin through 4.57 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.
Technical Analysis
REMEDIATION: Update to version 4.58, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C