CVE-2022-2839: Zephyr Project Manager < 3.2.55 - Unauthorised AJAX Calls To Stored XSS
The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJAX actions, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored Cross-Site Scripting attacks against logged in admins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2839?
The severity of CVE-2022-2839 is classified as high due to the potential for unauthorized access and execution of AJAX actions.
How do I fix CVE-2022-2839?
To fix CVE-2022-2839, update the Zephyr Project Manager plugin to version 3.2.55 or later.
Who is affected by CVE-2022-2839?
All users of the Zephyr Project Manager WordPress plugin prior to version 3.2.55 are affected by CVE-2022-2839.
What are the implications of CVE-2022-2839?
CVE-2022-2839 allows unauthenticated users to exploit AJAX actions, which could lead to data manipulation or exposure.
Does CVE-2022-2839 involve CSRF vulnerabilities?
Yes, CVE-2022-2839 includes CSRF vulnerabilities that can be exploited due to insufficient authorization and sanitization.