CVE-2017-20101: ProjectSend information disclosure
Published Jun 27, 2022
·Updated
A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the file process.php?do=zipdownload. The manipulation of the argument client/file leads to information disclosure. It is possible to initiate the attack remotely.
Affected Software
1 affected component
ProjectSend ProjectSend=r754
Event History
Jun 27, 2022
CVE Published
via MITRE·01:25 PM
Data Sourced
via MITRE·01:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2017-20101?
CVE-2017-20101 is a vulnerability that allows remote attackers to disclose information in ProjectSend r754.
2
How severe is CVE-2017-20101?
CVE-2017-20101 has a severity rating of 5.7 (medium).
3
How does CVE-2017-20101 affect ProjectSend r754?
CVE-2017-20101 affects an unknown part of the file process.php?do=zip_download in ProjectSend r754.
4
Can CVE-2017-20101 be exploited remotely?
Yes, CVE-2017-20101 can be exploited remotely.
5
Is there a fix for CVE-2017-20101?
There may be a fix available for CVE-2017-20101. It is recommended to check the official ProjectSend website or contact the vendor for the latest information.