Description
Projectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in returnFilesIds() function. A low privilege user can call this function through process.php file and execute scripting code.
Remediation
References
Related Vulnerabilities
b2evolution Use of Insufficiently Random Values Vulnerability (CVE-2022-30935)
WordPress Plugin Simple File Downloader Cross-Site Scripting (1.0.4)
Liferay DXP Insecure Default Initialization of Resource Vulnerability (CVE-2024-25610)
WordPress Plugin W4 Post List Multiple Vulnerabilities (2.4.5)
WordPress Plugin WP RSS By Publishers Multiple SQL Injection Vulnerabilities (0.1)