Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Sp_project_\&_document_manager
(Smartypantsplugins)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 13 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2024-05-15 | CVE-2024-3748 | The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user | Sp_project_\&_document_manager | N/A | ||
2024-05-15 | CVE-2024-3749 | The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user | Sp_project_\&_document_manager | N/A | ||
2024-02-28 | CVE-2024-24868 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager: from n/a through 4.69. | Sp_project_\&_document_manager | 8.8 |