CVE-2024-7658: projectsend process.php get_preview resource injection
A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the function getpreview of the file process.php. The manipulation leads to improper control of resource identifiers. The attack may be initiated remotely. Upgrading to version r1720 is able to address this issue. The patch is named eb5a04774927e5855b9d0e5870a2aae5a3dc5a08. It is recommended to upgrade the affected component.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7658?
CVE-2024-7658 has been classified as a problematic vulnerability affecting ProjectSend.
How does CVE-2024-7658 affect ProjectSend?
CVE-2024-7658 affects the function get_preview in process.php, leading to improper control of resource identifiers.
Can CVE-2024-7658 be exploited remotely?
Yes, CVE-2024-7658 can be exploited remotely, allowing attackers to manipulate resource identifiers.
How do I fix CVE-2024-7658?
To fix CVE-2024-7658, upgrade ProjectSend to a version greater than r1720.
Which versions of ProjectSend are affected by CVE-2024-7658?
CVE-2024-7658 affects ProjectSend versions up to and including r1605.