PT-2025-47065 · Unknown · Projectsend
Raducu Alexandru-Ionut
+1
·
Published
2025-11-16
·
Updated
2025-11-16
·
CVE-2025-13232
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ProjectSend versions prior to r1945
Description
A cross-site scripting issue exists in ProjectSend up to version r1720. The flaw is located within the File Editor/Custom Download Aliases component and involves an unknown function. This manipulation allows for remote execution of cross-site scripting. The exploit has been published.
Recommendations
Upgrade to version r1945 to address this issue.
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Projectsend