ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request parameter status, process-zip-download.php with the request parameter file, or home-log.php with the request parameter action.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HProjectsend
APPProjectsend582
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
Related vulnerabilities
CVE-2024-11680CRITICAL9.8⚠ KEVPL ✓same product
ProjectSend – pominięcie uwierzytelnienia umożliwiające RCE (r<1720)
CVE-2021-40887CRITICAL9.8PL ✓same product
Path traversal w ProjectSend r1295 — nieautoryzowany dostęp do plików
CVE-2016-10734CRITICAL9.8PL ✓same product
ProjectSend r582 — Insecure Direct Object Reference w eksporcie logów
CVE-2016-10733CRITICAL9.8PL ✓same product
Path traversal w ProjectSend r582 — dostęp do plików spoza katalogu
CVE-2016-10732CRITICAL9.8PL ✓same product
ProjectSend r582 — Authentication Bypass poprzez bezpośrednie żądania HTTP