PT-2025-51968 · Unknown · Projectsend

Mirabbas Ağalarov

·

Published

2025-12-17

·

Updated

2025-12-26

·

CVE-2023-53930

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ProjectSend version r1605
Description An insecure direct object reference issue exists in ProjectSend r1605. An unauthenticated attacker can download private files by manipulating the id parameter in a download request to the 'process.php' endpoint. This allows access to any user's private files.
Recommendations Apply appropriate access controls to the 'process.php' endpoint to prevent unauthorized file downloads. Sanitize or validate the id parameter to ensure it corresponds to a legitimate file accessible to the requesting user.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2023-53930

Affected Products

Projectsend