Projectsend r1295 Stored Cross-Site Scripting via files-edit.php
Vulnerability Description
Projectsend r1295 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input in the 'name' parameter of files-edit.php. Attackers can inject JavaScript payloads through the file name field that execute in the browser when the file is viewed by other users, particularly affecting System Administrator users on the Dashboard page.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47947
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Abdullah Kala
Affected Vendor
Projectsend
View all reports →