Arbitrary Code Execution Vulnerability in ProjectSend by ProjectSend Team
CVE-2017-9741
9.8CRITICAL
What is CVE-2017-9741?
A vulnerability in ProjectSend allows remote attackers to execute arbitrary PHP code through manipulation of the dbprefix parameter in install/make-config.php. This exploitation can occur due to improper handling of the TABLES_PREFIX definition in the configuration file, presenting a significant security risk to the affected installations.