CVE-2021-40884
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/10/2021
Last modified:
12/07/2022
Description
Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php and id parameter in process.php function, a user with uploader role can download and edit all files of users in application.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
5.50
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:projectsend:projectsend:r1295:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page