CVE-2020-28874
26.01.2021, 18:15
reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).Enginsight
Vendor | Product | Version |
---|---|---|
projectsend | projectsend | 𝑥 < r1295 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References