Cross-Site Scripting Vulnerability in ProjectSend by ProjectSend
CVE-2019-11533

6.1MEDIUM

Key Information:

Vendor
CVE Published:
26 April 2019

What is CVE-2019-11533?

A cross-site scripting vulnerability exists in ProjectSend versions prior to r1070, enabling remote attackers to inject arbitrary web scripts or HTML into the application. This flaw can be exploited to manipulate user sessions, redirect users to malicious sites, or steal sensitive information, posing significant security risks for users of affected versions.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.