CVE-2024-3748
The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user
- Affected products
- Sp Project & Document Manager
- Smartypantsplugins Sp Project \& Document Manager
- ≤ 4.71
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.4% (37th percentile)
- NVD status
- Analyzed
- Published
- 2024-05-15
CVE-2024-3748 at NVD
1 known exploit for CVE-2024-3748
Proof-of-concept code and exploit modules indexed by Sploitus