CVE-2024-38761 is a high-severity (CVSS 7.5) information exposure vulnerability affecting Dylan James Zephyr Project Manager versions up to 3.3.99. This flaw allows an unauthorized actor to gain access to sensitive information without requiring any user interaction or complex attack methods. While the vulnerability presents a significant risk for data confidentiality, there is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.3.100CPE matchmatch criteria | cpe:2.3:a:zephyr-one:zephyr_project_manager:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.