PT-2025-51968 · Unknown · Projectsend
Mirabbas Ağalarov
·
Publicado
2025-12-17
·
Atualizado
2025-12-26
·
CVE-2023-53930
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ProjectSend version r1605
Description
An insecure direct object reference issue exists in ProjectSend r1605. An unauthenticated attacker can download private files by manipulating the
id parameter in a download request to the 'process.php' endpoint. This allows access to any user's private files.Recommendations
Apply appropriate access controls to the 'process.php' endpoint to prevent unauthorized file downloads.
Sanitize or validate the
id parameter to ensure it corresponds to a legitimate file accessible to the requesting user.Exploit
Correção
IDOR
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Projectsend