CVE-2023-31237: WordPress Zephyr Project Manager Plugin <= 3.3.9 is vulnerable to Open Redirection
Published Dec 29, 2023
·Updated
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.9.
Affected Software
1 affected component
Zephyr Project Manager Project Zephyr Project Manager Wordpress<3.3.91
Remediation
Information
Update to 3.3.91 or a higher version.
Event History
Dec 29, 2023
CVE Published
via MITRE·09:56 AM
Data Sourced
via MITRE·09:56 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-31237?
CVE-2023-31237 is considered a medium severity vulnerability due to the likelihood of exploitation through URL redirection.
2
How do I fix CVE-2023-31237?
To fix CVE-2023-31237, update Zephyr Project Manager plugin to a version higher than 3.3.9.
3
What type of vulnerability is CVE-2023-31237?
CVE-2023-31237 is a URL Redirection to Untrusted Site vulnerability, commonly known as an Open Redirect.
4
Which versions of Zephyr Project Manager are affected by CVE-2023-31237?
CVE-2023-31237 affects all versions of Zephyr Project Manager from n/a up to 3.3.9.
5
Who is the vendor associated with CVE-2023-31237?
The vendor associated with CVE-2023-31237 is Dylan James, the maintainer of the Zephyr Project Manager.