CVE-2022-2840: Zephyr Project Manager < 3.2.5 - Multiple Unauthenticated SQLi
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2840?
CVE-2022-2840 is classified as a critical SQL injection vulnerability affecting the Zephyr Project Manager WordPress plugin.
How do I fix CVE-2022-2840?
To fix CVE-2022-2840, update the Zephyr Project Manager plugin to version 3.2.5 or later.
Who is affected by CVE-2022-2840?
CVE-2022-2840 affects all users of the Zephyr Project Manager WordPress plugin versions prior to 3.2.5.
What are the consequences of exploiting CVE-2022-2840?
Exploiting CVE-2022-2840 could allow attackers to execute arbitrary SQL queries, potentially compromising the database.
What versions of the Zephyr Project Manager are vulnerable to CVE-2022-2840?
Versions of the Zephyr Project Manager plugin before 3.2.5 are vulnerable to CVE-2022-2840.