CVE-2024-7658

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-7658
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-7658.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-7658
Published
2024-08-12T13:38:49Z
Modified
2025-01-14T00:27:26.157507Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the function get_preview of the file process.php. The manipulation leads to improper control of resource identifiers. The attack may be initiated remotely. Upgrading to version r1720 is able to address this issue. The patch is named eb5a04774927e5855b9d0e5870a2aae5a3dc5a08. It is recommended to upgrade the affected component.

References

Affected packages

Git / github.com/projectsend/projectsend

Affected ranges

Type
GIT
Repo
https://github.com/projectsend/projectsend
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

Stable
r1053
r1070
r1270
r1295
r1335
r1415
r1420
r1584
r1605
r559
r753
r754
r756