Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PHP files or any file on the system that has permissions to /upload/files/ folder.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HProjectsend
APPProjectsendr1295
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
Related vulnerabilities
CVE-2024-11680CRITICAL9.8⚠ KEVPL ✓same product
ProjectSend – pominięcie uwierzytelnienia umożliwiające RCE (r<1720)
CVE-2016-10733CRITICAL9.8PL ✓same product
Path traversal w ProjectSend r582 — dostęp do plików spoza katalogu
CVE-2016-10731CRITICAL9.8PL ✓same product
SQL injection w wielu plikach ProjectSend r582
CVE-2016-10732CRITICAL9.8PL ✓same product
ProjectSend r582 — Authentication Bypass poprzez bezpośrednie żądania HTTP
CVE-2016-10734CRITICAL9.8PL ✓same product
ProjectSend r582 — Insecure Direct Object Reference w eksporcie logów