vendor:
projectSend
by:
Mirabbas Agalarov
7.5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: projectSend
Affected Version From: r1605
Affected Version To: r1605
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
2023
projectSend r1605 – Remote Code Execution RCE
The attacker exploits a vulnerability in projectSend r1605 through file extension manipulation. By uploading a file with a manipulated file extension, the attacker is able to execute arbitrary code on the target system.
Mitigation:
Update to a patched version of projectSend that addresses the vulnerability. Avoid uploading files with manipulated file extensions.