CVE-2024-3748
EUVD-2024-3232115.05.2024, 06:15
The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another userEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| smartypantsplugins | sp_project_\&_document_manager | 𝑥 ≤ 4.71 |
𝑥
= Vulnerable software versions