CRITICAL
ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_* parameters to users-add.php
Published Oct 28, 2018
9.8
CRITICALCVSS 3.0
EPSS 1.85%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.