CVE-2023-53930

Source
https://cve.org/CVERecord?id=CVE-2023-53930
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53930.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-53930
Published
2025-12-17T22:44:57Z
Modified
2026-08-12T03:51:15Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
ProjectSend r1605 Insecure Direct Object Reference File Download Vulnerability
Details

ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changing the 'id' parameter in the download request to process.php.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53930.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "r1605"
                },
                {
                    "last_affected": "r1605"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/projectsend/projectsend

Affected ranges

Type
GIT
Repo
https://github.com/projectsend/projectsend
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:projectsend:projectsend:r1605:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "r1605"
        },
        {
            "last_affected": "r1605"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

Other
r1605

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53930.json"