The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Metrics
Affected Vendors & Products
References
History
Mon, 04 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dylanjames
Dylanjames zephyr Project Manager |
|
CPEs | cpe:2.3:a:dylanjames:zephyr_project_manager:*:*:*:*:*:*:*:* | |
Vendors & Products |
Dylanjames
Dylanjames zephyr Project Manager |
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-11-04T16:38:26.463Z
Reserved: 2024-07-05T20:00:20.656Z
Link: CVE-2024-6536

Updated: 2024-08-01T21:41:03.512Z

Status : Awaiting Analysis
Published: 2024-07-30T06:15:04.013
Modified: 2024-11-21T09:49:50.537
Link: CVE-2024-6536

No data.