Loading
Generated remediation guidance and an executive summary. No account required.
ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changing the 'id' parameter in the download request to process.php.
Use CWE-639, Projectsend vendor hub and Projectsend product page to widen CVE-2023-53930 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-11680, CVE-2021-40887 and CVE-2023-53980 for nearby disclosures in the same product family.