What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99.
Explanation of Vulnerability in Simple Terms
Zephyr Project Manager versions up to 3.3.99 expose sensitive information to unauthenticated attackers over the network. The vulnerability allows direct access to confidential data without requiring authentication or user interaction. No integrity or availability impact has been reported. Organizations using affected versions should update immediately.
What an attacker can do
Read sensitive information from the application without authentication.
Potential impact on your site
Confidential data stored in Zephyr Project Manager is accessible to anyone on the network.
Conditions required to exploit
Network access to the application; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities