Projectsend

Projectsend

32 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 06.04.2026 05:00:19
  • Zuletzt bearbeitet 07.04.2026 13:20:35

A security flaw has been discovered in ProjectSend r2002. This vulnerability affects unknown code of the file upload.php. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit has been rele...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 12.03.2026 16:02:07
  • Zuletzt bearbeitet 12.03.2026 21:07:53

A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php. Executing a manipulation of the argument ldap_email can lead to observable response discrepancy. The attack can be executed remo...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 12.03.2026 15:32:11
  • Zuletzt bearbeitet 12.03.2026 21:07:53

A vulnerability was detected in projectsend up to r1945. This affects the function realpath of the file /import-orphans.php of the component Delete Handler. Performing a manipulation of the argument files[] results in path traversal. Remote exploitat...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 22.12.2025 21:35:36
  • Zuletzt bearbeitet 26.12.2025 15:40:38

ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by manipulating file extensions. Attackers can upload shell scripts with disguised extensions through the upload.process.php endpoint to ...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 17.12.2025 22:44:57
  • Zuletzt bearbeitet 27.12.2025 17:15:44

ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changing the 'id'...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 17.12.2025 22:44:45
  • Zuletzt bearbeitet 27.12.2025 17:15:42

projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft a JavaScript payload in the custom assets...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 17.12.2025 22:44:44
  • Zuletzt bearbeitet 27.12.2025 17:15:42

ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attackers can craft payloads like =calc|a!z| in the name field to trigger code execution when administrator...

Warnung Exploit
  • EPSS 93.49%
  • Veröffentlicht 26.11.2024 10:15:04
  • Zuletzt bearbeitet 31.10.2025 21:56:27

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the applicati...

  • EPSS 0.22%
  • Veröffentlicht 12.08.2024 13:38:49
  • Zuletzt bearbeitet 15.08.2024 17:49:42

A vulnerability, which was classified as problematic, was found in projectsend up to r1605. Affected is the function generate_random_string of the file includes/functions.php of the component Password Reset Token Handler. The manipulation leads to in...

  • EPSS 0.25%
  • Veröffentlicht 12.08.2024 13:38:49
  • Zuletzt bearbeitet 13.01.2025 21:15:14

A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the function get_preview of the file process.php. The manipulation leads to improper control of resource identifiers. The attack may b...