CyberSec.Space Logo
CVEブラウザに戻る

CVE-2023-53930

HIGH
7.1
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-12-17
Last Modified2026-06-17
Data SourcesNVD

Vulnerability Description

ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changing the 'id' parameter in the download request to process.php.

Affected Platforms (CPE)

📦
Projectsend

Projectsend

= r1605

References & Advisories

関連する脆弱性情報