Description
Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php and id parameter in process.php function, a user with uploader role can download and edit all files of users in application.
Remediation
References
Related Vulnerabilities
GlassFish CVE-2018-3210 Vulnerability (CVE-2018-3210)
WordPress Plugin WP Cost Estimation & Payment Forms Builder Directory Traversal (9.659)
WordPress Plugin Limit Login Attempts Reloaded Security Bypass (2.7.4)
ownCloud Generation of Error Message Containing Sensitive Information Vulnerability (CVE-2021-35947)