Логотип exploitDog
bind:CVE-2023-53930
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-53930

Количество 2

Количество 2

nvd логотип

CVE-2023-53930

около 2 месяцев назад

ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changing the 'id' parameter in the download request to process.php.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-gc6r-xc3x-9vvg

около 2 месяцев назад

ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changing the 'id' parameter in the download request to process.php.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-53930

ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changing the 'id' parameter in the download request to process.php.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-gc6r-xc3x-9vvg

ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changing the 'id' parameter in the download request to process.php.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу