CVE-2023-53930: ProjectSend r1605 Insecure Direct Object Reference File Download Vulnerability
ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changing the 'id' parameter in the download request to process.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53930?
CVE-2023-53930 is considered a high severity vulnerability due to its potential for unauthorized access to private user files.
How does CVE-2023-53930 work?
CVE-2023-53930 exploits an insecure direct object reference, allowing attackers to manipulate the download ID parameter to access private files.
Who is affected by CVE-2023-53930?
CVE-2023-53930 affects users of ProjectSend versions prior to r1605.
How do I fix CVE-2023-53930?
To mitigate CVE-2023-53930, users should upgrade ProjectSend to version r1605 or later.
What are the risks of CVE-2023-53930?
The risks associated with CVE-2023-53930 include unauthorized file downloads, potential data breaches, and exposure of sensitive user information.