PT-2026-24962 · Undefined · Undefined

0Xnayel

+1

·

Publicado

2026-03-12

·

Atualizado

2026-03-30

·

CVE-2026-4044

CVSS v2.0

4.7

Média

VetorAV:N/AC:L/Au:M/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions projectsend versions prior to r1945
Description A flaw exists in projectsend that allows for path traversal. This issue affects the realpath function within the /import-orphans.php file of the Delete Handler component. Manipulating the files[] argument can lead to unauthorized access. Remote exploitation is possible, and an exploit is publicly available. The vendor was notified but did not respond.
Recommendations Update projectsend to a version later than r1945. As a temporary workaround, restrict access to the /import-orphans.php file.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4044

Produtos afetados

Undefined