5.7

CVE-2017-20101

Exploit

ProjectSend information disclosure

A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the file process.php?do=zip_download. The manipulation of the argument client/file leads to information disclosure. It is possible to initiate the attack remotely.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Projectsend ≫ Projectsend Version r754
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.04% 0.595
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.7 2.1 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
NIST 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:P/I:N/A:N
cna@vuldb.com 3.5 2.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

http://seclists.org/fulldisclosure/2017/Feb/58
Third Party Advisory
Exploit
Mailing List
https://vuldb.com/?id.97275
Third Party Advisory
https://youtu.be/Xc6Jg9I7Pj4
Third Party Advisory
Exploit