CVE-2020-28874: High severity ProjectSend ProjectSend vulnerability
Published Jan 21, 2021
·Updated
reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).
Affected Software
1 affected component
ProjectSend ProjectSend<r1295
Remediation
Patch Available
Event History
Jan 21, 2021
CVE Published
via MITRE·03:01 PM
Data Sourced
via MITRE·03:01 PM
Description
Jan 26, 2021
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-28874?
CVE-2020-28874 is a vulnerability in ProjectSend before r1295 that allows remote attackers to reset a password due to incorrect business logic and errors not being properly considered.
2
How severe is CVE-2020-28874?
CVE-2020-28874 has a severity rating of 7.5 (High).
3
What software is affected by CVE-2020-28874?
ProjectSend before r1295 is affected by CVE-2020-28874.
4
How can the CVE-2020-28874 vulnerability be fixed?
To fix the CVE-2020-28874 vulnerability, update ProjectSend to version r1295 or later.
5
What is the Common Weakness Enumeration (CWE) for CVE-2020-28874?
The Common Weakness Enumeration (CWE) for CVE-2020-28874 is CWE-287 and CWE-404.