CVE-2024-38761: WordPress Zephyr Project Manager plugin <= 3.3.99 - Sensitive Data Exposure via Export File vulnerability
Published Aug 1, 2024
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99.
Affected Software
3 affected components
Zephyr-one Zephyr Project Manager Wordpress<3.3.100
Dylan James Zephyr Project Manager>=n/a<3.3.99
WordPress Zephyr Project Manager plugin<=3.3.99
Remediation
Information
Update to 3.3.100 or a higher version.
Event History
Aug 1, 2024
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-38761?
CVE-2024-38761 has been classified as a Moderate severity vulnerability.
2
How do I fix CVE-2024-38761?
To address CVE-2024-38761, upgrade Zephyr Project Manager to version 3.3.100 or later.
3
What does CVE-2024-38761 affect?
CVE-2024-38761 affects Zephyr Project Manager versions from n/a through 3.3.99.
4
Who is the vendor for CVE-2024-38761?
The vendor for CVE-2024-38761 is Dylan James.
5
What type of vulnerability is CVE-2024-38761?
CVE-2024-38761 is classified as an Exposure of Sensitive Information to an Unauthorized Actor vulnerability.