ZeroHour

CVE-2019-11378

PoC
CVSS 3.0
8.8 high
EPSS
4%p89
Published
()
Modified
Description

An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. It is possible for users to read arbitrary files and (potentially) access the supporting database, delete arbitrary files, access user passwords, or run arbitrary code.

Vendors
projectsend
Products
projectsend
Weakness
CWE-22
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.