Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
projectsend projectsend vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2019-11492
ProjectSend before r1070 writes user passwords to the server logs.
Projectsend Projectsend
6.5
CVSSv3
CVE-2021-40886
Projectsend version r1295 is affected by a directory traversal vulnerability. A user with Uploader role can add value `2` for `chunks` parameter to bypass `fileName` sanitization.
Projectsend Projectsend R1295
6.1
CVSSv3
CVE-2018-7202
An issue exists in ProjectSend before r1053. XSS exists in the "Name" field on the My Account page.
Projectsend Projectsend
6.1
CVSSv3
CVE-2019-11533
Cross-site scripting (XSS) vulnerability in ProjectSend before r1070 allows remote malicious users to inject arbitrary web script or HTML.
Projectsend Projectsend
6.1
CVSSv3
CVE-2017-9786
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote malicious users to inject arbitrary web script or HTML via the Description field in My account Name updated, related to home.php and action...
Projectsend Projectsend
6.1
CVSSv3
CVE-2017-9783
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote malicious users to inject arbitrary web script or HTML via the Description field in a Site name updated.
Projectsend Projectsend
5.7
CVSSv3
CVE-2017-20101
A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the file process.php?do=zip_download. The manipulation of the argument client/file leads to information disclosure. It is possible to initiate the attack remotely.
Projectsend Projectsend R754
5.4
CVSSv3
CVE-2021-40888
Projectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in returnFilesIds() function. A low privilege user can call this function through process.php file and execute scripting code.
Projectsend Projectsend R1295
4.8
CVSSv3
CVE-2023-0607
Cross-site Scripting (XSS) - Stored in GitHub repository projectsend/projectsend prior to r1606.
Projectsend Projectsend
NA
CVE-2018-13452
ProjectSend version R1053 suffers from a remote SQL injection vulnerability.
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-22120
CVE-2024-35921
CVE-2024-35874
brute force
CVE-2024-36080
unprivileged
CVE-2024-35917
IDOR
CVE-2024-4947
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »