Vulnerability Description
Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PHP files or any file on the system that has permissions to /upload/files/ folder.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Projectsend | Projectsend | r1295 |
Related Weaknesses (CWE)
References
- https://github.com/projectsend/projectsend/issues/994ExploitThird Party Advisory
- https://github.com/projectsend/projectsend/issues/994ExploitThird Party Advisory
FAQ
What is CVE-2021-40887?
CVE-2021-40887 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PHP files or any file on ...
How severe is CVE-2021-40887?
CVE-2021-40887 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-40887?
Check the references section above for vendor advisories and patch information. Affected products include: Projectsend Projectsend.