vendor:
Projectsend
by:
Abdullah Kala
N/A
CVSS
N/A
Stored XSS
CWE
Product Name: Projectsend
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Ubuntu 18.04
2021
Projectsend r1295 – ‘name’ Stored XSS
Firstly add client group. After uploading the file from the user with any role, payload is written in the 'title' part of the redirected page, add group your created and save. For users with the 'System Administrator' role, XSS is triggered on the 'Dashboard' page.
Mitigation:
Unknown