PT-2019-11092 · Projectsend · Projectsend

Published

2019-05-22

·

Updated

2019-05-23

·

CVE-2018-7202

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: ProjectSend versions prior to r1053
Description: An issue exists where XSS is present in the Name field on the My Account page, allowing for potential exploitation.
Recommendations: For versions prior to r1053, update to version r1053 or later to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-7202

Affected Products

Projectsend