Zephyr Project Manager < 3.2.55 - Missing Authorization to Cross-Site Scripting

2022-09-08 00:00
Rizacan Tufan

Strategic Overview

Status
Patched in 3.2.55
Affected PluginZephyr Project Manager
Affected Version< 3.2.55
CVSS7.2High
CVECVE-2022-2839
View all Zephyr Project Manager vulnerabilities

Vulnerability Overview

The Zephyr Project Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and lack of authentication/authorization on its AJAX endpoints in versions up to 3.2.55. This makes it possible for unauthenticated attackers to utilize them. Additionally, user input is not properly sanitized leading to Stored Cross-Site Scripting.

Technical Analysis

REMEDIATION: Update to version 3.2.55, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C