Description ProjectSend before r1070 writes user passwords to the server logs. Remediation References CVE-2019-11492 Related Vulnerabilities ownCloud Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2016-1498) WordPress Plugin Vitamin Multiple Arbitrary File Disclosure Vulnerabilities (1.0.0) Dotclear Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-1039) WordPress Plugin Easy WP SMTP Security Bypass (1.4.2) MySQL CVE-2019-2810 Vulnerability (CVE-2019-2810) Severity High Classification CVE-2019-11492 CWE-532 Tags Missing Update Known Vulnerabilities