Improper Control of Resource Identifiers in File Process.php Could Allow Remote Code Execution
CVE-2024-7658
5.3MEDIUM
Key Information
- Vendor
- projectsend
- Status
- Projectsend
- Vendor
- CVE Published:
- 12 August 2024
Summary
A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the function get_preview of the file process.php. The manipulation leads to improper control of resource identifiers. The attack may be initiated remotely. Upgrading to version r1720 is able to address this issue. The patch is named eb5a04774927e5855b9d0e5870a2aae5a3dc5a08. It is recommended to upgrade the affected component.
Affected Version(s)
projectsend = r1605
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published.
Risk change from: null to: 5.3 - (MEDIUM)
VulDB entry last update
Vulnerability Reserved.
VulDB entry created
Advisory disclosed
Collectors
NVD DatabaseMitre Database
Credit
Casp3r0x0 (VulDB User)