Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-40884

Опубликовано: 11 окт. 2021
Источник: nvd
CVSS3: 8.1
CVSS2: 5.5
EPSS Низкий

Описание

Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php and id parameter in process.php function, a user with uploader role can download and edit all files of users in application.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:projectsend:projectsend:r1295:*:*:*:*:*:*:*

EPSS

Процентиль: 49%
0.00258
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php and id parameter in process.php function, a user with uploader role can download and edit all files of users in application.

EPSS

Процентиль: 49%
0.00258
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-862