Vulnerabilities (CVE)

Filtered by vendor Projectsend Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-40884 1 Projectsend 1 Projectsend 2022-07-12 5.5 MEDIUM 8.1 HIGH
Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php and id parameter in process.php function, a user with uploader role can download and edit all files of users in application.
CVE-2020-28874 1 Projectsend 1 Projectsend 2021-07-21 5.0 MEDIUM 7.5 HIGH
reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).
CVE-2019-11378 1 Projectsend 1 Projectsend 2021-07-21 6.5 MEDIUM 8.8 HIGH
An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. It is possible for users to read arbitrary files and (potentially) access the supporting database, delete arbitrary files, access user passwords, or run arbitrary code.
CVE-2018-7201 1 Projectsend 1 Projectsend 2020-08-24 6.8 MEDIUM 8.8 HIGH
CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.
CVE-2019-11492 1 Projectsend 1 Projectsend 2019-04-30 5.0 MEDIUM 7.5 HIGH
ProjectSend before r1070 writes user passwords to the server logs.