vendor:
projectSend
by:
Mirabbas Agalarov
7.5
CVSS
HIGH
IDOR
CWE
Product Name: projectSend
Affected Version From: r1605
Affected Version To: r1605
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
2023
projectSend r1605 – Private file download
Access to private files of any user, including admin by changing the id in the GET request.
Mitigation:
Implement proper access control and authentication mechanisms.