Lucene search

K
wpvulndbWpvulndbWPVDB-ID:C30B2378-59D4-4C2E-8C65-EA9772BA96CB
HistoryJun 29, 2023 - 12:00 a.m.

SP Project & Document Manager < 4.68 - Subscriber+ Insecure Direct Object References

2023-06-2900:00:00
wpscan.com
8
sp project & document manager
unauthorized access
password changes

EPSS

0.001

Percentile

39.7%

The plugin allows direct access to objects, allowing an authenticated user with subscriber privileges or above, to bypass authorization and change user passwords and potentially take over administrator accounts.

EPSS

0.001

Percentile

39.7%

Related for WPVDB-ID:C30B2378-59D4-4C2E-8C65-EA9772BA96CB