Projectsend

Projectsend

29 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.85%
  • Veröffentlicht 11.10.2021 11:15:09
  • Zuletzt bearbeitet 21.11.2024 06:25:00

Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PHP files or any file on the system that has permissions to /upload/files/ ...

Exploit
  • EPSS 0.6%
  • Veröffentlicht 11.10.2021 11:15:09
  • Zuletzt bearbeitet 21.11.2024 06:25:00

Projectsend version r1295 is affected by a directory traversal vulnerability. A user with Uploader role can add value `2` for `chunks` parameter to bypass `fileName` sanitization.

Exploit
  • EPSS 0.22%
  • Veröffentlicht 11.10.2021 11:15:09
  • Zuletzt bearbeitet 21.11.2024 06:25:00

Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php and id parameter in process.php function, a user with uploader role can download and edit all files of...

Exploit
  • EPSS 1.36%
  • Veröffentlicht 26.01.2021 18:15:51
  • Zuletzt bearbeitet 21.11.2024 05:23:13

reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).

  • EPSS 0.42%
  • Veröffentlicht 22.05.2019 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:11:46

CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.

  • EPSS 0.24%
  • Veröffentlicht 22.05.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 04:11:46

An issue was discovered in ProjectSend before r1053. XSS exists in the "Name" field on the My Account page.

  • EPSS 0.23%
  • Veröffentlicht 26.04.2019 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:21:17

Cross-site scripting (XSS) vulnerability in ProjectSend before r1070 allows remote attackers to inject arbitrary web script or HTML.

  • EPSS 0.32%
  • Veröffentlicht 26.04.2019 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:21:11

ProjectSend before r1070 writes user passwords to the server logs.

Exploit
  • EPSS 2.49%
  • Veröffentlicht 20.04.2019 15:29:01
  • Zuletzt bearbeitet 21.11.2024 04:20:59

An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. It is possible for users to read arbitrary files and (potentially) access the supporting database, delete arbitrary files, access u...

  • EPSS 0.35%
  • Veröffentlicht 29.10.2018 12:29:01
  • Zuletzt bearbeitet 21.11.2024 02:44:37

ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.