The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the user_id
to make it appear that a file was uploaded by another user
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sp_project_&_document_manager | Smartypantsplugins | * | 4.71 (including) |