Impact
ProjectSend r2029 has a reflected cross‑site scripting vulnerability located in thumbnails‑regenerate.php. Unsanitized start_date and end_date GET parameters are inserted unescaped into HTML attribute values, allowing attackers to craft URLs that inject arbitrary HTML and JavaScript. When an authenticated user with edit_settings permissions requests the malicious URL, the injected scripts execute within the application origin. This can be exploited to steal session cookies or perform unauthorized actions such as user management, file management, and application setting changes.
Affected Systems
The flaw affects the ProjectSend project, specifically versions up to and including r2029.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity vulnerability. The EPSS score is not provided, and the issue is not listed in the CISA KEV catalog. The attack requires the victim to be logged in with edit_settings permissions and to follow a specially crafted URL that supplies malicious start_date and end_date values. Given the medium severity and lack of publicly known exploits, the risk is moderate, but the potential impact on confidentiality and integrity remains significant.
OpenCVE Enrichment