CVE-2019-11378

Source
https://cve.org/CVERecord?id=CVE-2019-11378
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11378.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-11378
Published
2019-04-20T15:29:01.027Z
Modified
2026-03-14T09:31:51.014909Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. It is possible for users to read arbitrary files and (potentially) access the supporting database, delete arbitrary files, access user passwords, or run arbitrary code.

References

Affected packages

Git / github.com/projectsend/projectsend

Affected ranges

Type
GIT
Repo
https://github.com/projectsend/projectsend
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "r1053"
        }
    ]
}

Affected versions

Other
r1053
r559
r753
r754
r756

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11378.json"