Description ProjectSend before r1070 writes user passwords to the server logs. Remediation References CVE-2019-11492 Related Vulnerabilities WebLogic Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2022-21371) WordPress Plugin Swiss Toolkit For WP Security Bypass (1.0.8) WordPress Plugin Active Directory Integration/LDAP Integration Cross-Site Scripting (3.6.94) Dolibarr Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-16197) Dolibarr Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-16686) Severity High Classification CVE-2019-11492 CWE-532 Tags Missing Update Known Vulnerabilities