CVE-2024-43322: WordPress Zephyr Project Manager plugin <= 3.3.100 - Insecure Direct Object References (IDOR) vulnerability
Published Aug 18, 2024
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.100.
Affected Software
3 affected components
Zephyr-one Zephyr Project Manager Wordpress<3.3.101
Dylan James Zephyr Project Manager<=3.3.100
WordPress Zephyr Project Manager plugin<=3.3.100
Remediation
Information
Update to 3.3.101 or a higher version.
Event History
Aug 18, 2024
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 4, 57087
Event
via NVD·02:37 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-43322?
CVE-2024-43322 has been assigned a high severity rating due to its potential for authorization bypass.
2
How do I fix CVE-2024-43322?
To fix CVE-2024-43322, upgrade Zephyr Project Manager to version 3.3.101 or later.
3
Who is affected by CVE-2024-43322?
CVE-2024-43322 affects all versions of Zephyr Project Manager up to and including 3.3.100.
4
What type of vulnerability is CVE-2024-43322?
CVE-2024-43322 is an authorization bypass vulnerability that can be exploited through user-controlled keys.
5
Is there a workaround for CVE-2024-43322?
Currently, there are no known workarounds for CVE-2024-43322 other than upgrading the software.