varandinawer/CVE-2020-28874

varandinawer/CVE-2020-28874

Releases0
CVE-2020-28874

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).