Description
Projectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in returnFilesIds() function. A low privilege user can call this function through process.php file and execute scripting code.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2006-0259 Vulnerability (CVE-2006-0259)
WordPress 3.7.x PHP Object Injection (3.7 - 3.7.35)
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-37911)
Python Divide By Zero Vulnerability (CVE-2017-18207)
WordPress Plugin Bootstrap Categories Gallery Cross-Site Scripting (1.0.1)