SP Project & Document Manager <= 4.57 - Sensitive File Disclosure

2022-06-28 00:00
Viktor Markopoulos

Strategic Overview

Status
Patched in 4.58
Affected Version<= 4.57
CVSS5.3Medium
CVECVE-2022-1551
View all SP Project & Document Manager vulnerabilities

Vulnerability Overview

The SP Project & Document Manager WordPress plugin through 4.57 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.

Technical Analysis

REMEDIATION: Update to version 4.58, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C