Missing Authorization Vulnerability in ProjectSend AJAX Endpoints
CVE-2026-3977
5.3MEDIUM
What is CVE-2026-3977?
A security issue has been identified in ProjectSend up to version r1945, specifically within the AJAX Endpoints component. This vulnerability arises from a failure to enforce proper authorization controls, allowing attackers to exploit this flaw remotely. To mitigate this risk, deploying the patch with the identifier 35dfd6f08f7d517709c77ee73e57367141107e6b is highly recommended to secure the affected systems.
Affected Version(s)
projectsend r1945
