CVE-2021-40887: Path Traversal
Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PHP files or any file on the system that has permissions to /upload/files/ folder.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ProjectSendto a version that resolves this vulnerability.Fixed in r1295Patch directory traversal vulnerability
Event History
Frequently Asked Questions
What is CVE-2021-40887?
CVE-2021-40887 is a directory traversal vulnerability in Projectsend version r1295.
How severe is CVE-2021-40887?
CVE-2021-40887 has a severity rating of 9.8 (Critical).
What software versions are affected by CVE-2021-40887?
Projectsend version r1295 is affected by CVE-2021-40887.
What is the impact of CVE-2021-40887?
CVE-2021-40887 allows an attacker to perform directory traversal, potentially granting unauthorized access to sensitive files on the system.
Is there a fix available for CVE-2021-40887?
At the time of writing, there is no official fix available for CVE-2021-40887. It is recommended to update to the latest version of Projectsend when a fix becomes available.