Cross-Site Scripting Vulnerability in ProjectSend File Editor Component
CVE-2025-13232
What is CVE-2025-13232?
A significant cross-site scripting vulnerability has been identified in the File Editor/Custom Download Aliases component of ProjectSend. This flaw allows attackers to execute arbitrary scripts in the context of the user's browser, which can lead to unauthorized access and manipulation of user data. The vulnerability is exploitable remotely, emphasizing the importance of immediate action. Users are strongly advised to upgrade to version r1945 or later to mitigate this risk effectively. The recent patch, identified as commit 334da1ea39cb12f6b6e98dd2f80bb033e0c7b845, provides a comprehensive fix to this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
projectsend r1720
projectsend r1945
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
