CVE-2022-2840
critical · 9.8The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
9.8
CVSS
12.9%
EPSS (exploit prob.)
96th
EPSS percentile
2022-09-19
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-89
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| zephyr-one | zephyr_project_manager | < 3.2.5 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/168652/WordPress-Zephyr-Project-Manager-3.2.42-SQL-Injection.html
- https://wpscan.com/vulnerability/13d8be88-c3b7-4d6e-9792-c98b801ba53c
- http://packetstormsecurity.com/files/168652/WordPress-Zephyr-Project-Manager-3.2.42-SQL-Injection.html
- https://wpscan.com/vulnerability/13d8be88-c3b7-4d6e-9792-c98b801ba53c
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-2840