CVE-2024-3749
MEDIUMDescription
The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user
Is your site exposed to CVE-2024-3749?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| smartypantsplugins | sp_project_\&_document_manager |
References
Frequently Asked Questions
What is CVE-2024-3749? +
How severe is CVE-2024-3749? +
What products are affected by CVE-2024-3749? +
How do I check if I'm vulnerable to CVE-2024-3749? +
Related Vulnerabilities
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This …
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in smartypants SP Project & Document Manager.This issue …
The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user …