PT-2026-25004 · Undefined · Undefined

0Xnayel

+1

·

Publicado

2026-03-12

·

Atualizado

2026-03-30

·

CVE-2026-4045

CVSS v3.1

3.7

Baixa

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions projectsend versions prior to r1946
Description A flaw exists in projectsend up to revision r1945. This impacts an unknown function within the includes/Classes/Auth.php file. Manipulating the ldap email argument can cause an observable discrepancy in the response. The attack can be executed remotely and is associated with a high level of complexity. The exploit has been published. The vendor was contacted regarding this issue but did not respond.
Recommendations Update projectsend to version r1946 or later.

Exploit

Correção

Side Channel Attack

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4045

Produtos afetados

Undefined