PT-2025-47065 · Unknown · Projectsend

Raducu Alexandru-Ionut

+1

·

Published

2025-11-16

·

Updated

2025-11-16

·

CVE-2025-13232

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ProjectSend versions prior to r1945
Description A cross-site scripting issue exists in ProjectSend up to version r1720. The flaw is located within the File Editor/Custom Download Aliases component and involves an unknown function. This manipulation allows for remote execution of cross-site scripting. The exploit has been published.
Recommendations Upgrade to version r1945 to address this issue.

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-13232

Affected Products

Projectsend