Back

MEDIUM

projectsend process.php get_preview resource injection

Published Aug 11, 2024

Description

A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the function get_preview of the file process.php. The manipulation leads to improper control of resource identifiers. The attack may be initiated remotely. Upgrading to version r1720 is able to address this issue. The patch is named eb5a04774927e5855b9d0e5870a2aae5a3dc5a08. It is recommended to upgrade the affected component.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 11, 2024
Updated Jan 13, 2025
Reserved Aug 10, 2024
CISA Vulnrichment
Updated Aug 12, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulDB
Published Aug 11, 2024
Updated Jan 13, 2025
Exploited since n/a
EUVD-2024-48543