CVE-2019-11378: Path Traversal
An issue was discovered in ProjectSend r1053. upload-process-form.php allows finishedfiles[]=../ directory traversal. It is possible for users to read arbitrary files and (potentially) access the supporting database, delete arbitrary files, access user passwords, or run arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2019-11378.
What is the severity of CVE-2019-11378?
The severity of CVE-2019-11378 is high with a severity value of 8.8.
What is the affected software?
The affected software is ProjectSend r1053.
What is the impact of CVE-2019-11378?
The impact of CVE-2019-11378 is that it allows users to read arbitrary files, potentially access the supporting database, delete arbitrary files, access user passwords, or run arbitrary code.
Are there any known references for CVE-2019-11378?
Yes, you can find references for CVE-2019-11378 at the following links: http://www.securityfocus.com/bid/108069 and https://github.com/projectsend/projectsend/issues/700.