PT-2019-12269 · Projectsend · Projectsend

Lmsilva

·

Publicado

2019-04-20

·

Atualizado

2021-07-21

·

CVE-2019-11378

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ProjectSend version r1053
Description An issue was discovered that allows directory traversal through the upload-process-form.php file, potentially enabling users to read arbitrary files, access the supporting database, delete arbitrary files, access user passwords, or run arbitrary code.
Recommendations For ProjectSend version r1053, consider restricting access to the upload-process-form.php file until a patch is available to prevent directory traversal attacks. As a temporary workaround, limit the ability of users to upload files to prevent potential exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-11378

Produtos afetados

Projectsend