PT-2019-12269 · Projectsend · Projectsend

Lmsilva

·

Published

2019-04-20

·

Updated

2021-07-21

·

CVE-2019-11378

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ProjectSend version r1053
Description An issue was discovered that allows directory traversal through the upload-process-form.php file, potentially enabling users to read arbitrary files, access the supporting database, delete arbitrary files, access user passwords, or run arbitrary code.
Recommendations For ProjectSend version r1053, consider restricting access to the upload-process-form.php file until a patch is available to prevent directory traversal attacks. As a temporary workaround, limit the ability of users to upload files to prevent potential exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11378

Affected Products

Projectsend