GHSA-755x-386x-p26p
GitHub Security Advisory
⚠ Unreviewed
CRITICAL
Has CVE
Advisory Details
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: June 16, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.