CVE-2016-10734: Critical severity projectsend vulnerability
Published Oct 28, 2018
·Updated
ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.
Affected Software
1 affected component
ProjectSend ProjectSend=582
Event History
Oct 28, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is CVE-2016-10734?
CVE-2016-10734 is a vulnerability in ProjectSend (formerly cFTP) r582 that allows Insecure Direct Object Reference (IDOR) attacks via includes/actions.log.export.php.
2
How severe is CVE-2016-10734?
CVE-2016-10734 has a severity rating of 9.8 (critical).
3
What software version is affected by CVE-2016-10734?
ProjectSend version r582 is affected by CVE-2016-10734.
4
What is Insecure Direct Object Reference (IDOR)?
Insecure Direct Object Reference (IDOR) is a vulnerability that allows an attacker to access unauthorized resources or perform actions by manipulating object references.
5
Is there a fix available for CVE-2016-10734?
To fix CVE-2016-10734, it is recommended to update to a version of ProjectSend that is not affected by this vulnerability.