PT-2026-24962 · Undefined · Undefined

0Xnayel

+1

·

Published

2026-03-12

·

Updated

2026-03-30

·

CVE-2026-4044

CVSS v2.0

4.7

Medium

VectorAV:N/AC:L/Au:M/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions projectsend versions prior to r1945
Description A flaw exists in projectsend that allows for path traversal. This issue affects the realpath function within the /import-orphans.php file of the Delete Handler component. Manipulating the files[] argument can lead to unauthorized access. Remote exploitation is possible, and an exploit is publicly available. The vendor was notified but did not respond.
Recommendations Update projectsend to a version later than r1945. As a temporary workaround, restrict access to the /import-orphans.php file.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-4044

Affected Products

Undefined