CVE-2021-38315
16.08.2021, 19:15
The SP Project & Document Manager WordPress plugin is vulnerable to attribute-based Reflected Cross-Site Scripting via the from and to parameters in the ~/functions.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.25.
Vendor | Product | Version |
---|---|---|
smartypantsplugins | sp_project_\&_document_manager | 𝑥 ≤ 4.25 |
𝑥
= Vulnerable software versions
References