Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php and id parameter in process.php function, a user with uploader role can download and edit all files of users in application.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-28039 Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php and id parameter in process.php function, a user with uploader role can download and edit all files of users in application.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T02:51:07.726Z

Reserved: 2021-09-13T00:00:00

Link: CVE-2021-40884

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-11T11:15:09.547

Modified: 2024-11-21T06:25:00.627

Link: CVE-2021-40884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.