Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-755x-386x-p26p

Опубликовано: 26 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

EPSS

Процентиль: 100%
0.9349
Критический

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-306
CWE-863

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 года назад

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

CVSS3: 9.8
fstec
около 1 года назад

Уязвимость программного обеспечения для обмена файлами ProjectSend связанная с недостатками процедуры аутентификации, позволяющая нарушителю выполнить изменение конфигурации приложения

EPSS

Процентиль: 100%
0.9349
Критический

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-306
CWE-863