Description
Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PHP files or any file on the system that has permissions to /upload/files/ folder.
Remediation
References
Related Vulnerabilities
WordPress 6.2.x Multiple Vulnerabilities (6.2 - 6.2.5)
PHP Improper Input Validation Vulnerability (CVE-2016-7129)
WordPress Plugin Catchers Helpdesk and Ticket system for Support Cross-Site Scripting (1.0.3)
Oracle Database Server CVE-2009-1992 Vulnerability (CVE-2009-1992)
WordPress Plugin WordPress File Upload Multiple Vulnerabilities (2.7.6)