Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Projectsend
(Projectsend)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 25 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-04-20 | CVE-2019-11378 | An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. It is possible for users to read arbitrary files and (potentially) access the supporting database, delete arbitrary files, access user passwords, or run arbitrary code. | Projectsend | 8.8 | ||
2019-05-22 | CVE-2018-7202 | An issue was discovered in ProjectSend before r1053. XSS exists in the "Name" field on the My Account page. | Projectsend | 6.1 | ||
2019-05-22 | CVE-2018-7201 | CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel. | Projectsend | 8.8 | ||
2019-04-26 | CVE-2019-11533 | Cross-site scripting (XSS) vulnerability in ProjectSend before r1070 allows remote attackers to inject arbitrary web script or HTML. | Projectsend | 6.1 | ||
2019-04-26 | CVE-2019-11492 | ProjectSend before r1070 writes user passwords to the server logs. | Projectsend | 7.5 | ||
2018-03-06 | CVE-2017-9786 | Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the Description field in My account Name updated, related to home.php and actions-log.php. | Projectsend | 6.1 | ||
2018-03-06 | CVE-2017-9783 | Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the Description field in a Site name updated. | Projectsend | 6.1 | ||
2017-06-18 | CVE-2017-9741 | install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLES_PREFIX in the configuration file. | Projectsend | 9.8 | ||
2018-10-29 | CVE-2016-10734 | ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php. | Projectsend | 9.8 | ||
2018-10-29 | CVE-2016-10733 | ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string. | Projectsend | 9.8 |