CVE-2022-1551
The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.
- Affected products
- Sp Project & Document Manager
- Smartypantsplugins Sp Project \& Document Manager
- < 4.58
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.9% (59th percentile)
- Weakness
- CWE-425
- NVD status
- Modified
- Published
- 2022-07-25
CVE-2022-1551 at NVD
1 known exploit for CVE-2022-1551
Proof-of-concept code and exploit modules indexed by Sploitus