Loading
Generated remediation guidance and an executive summary. No account required.
ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by manipulating file extensions. Attackers can upload shell scripts with disguised extensions through the upload.process.php endpoint to execute arbitrary commands on the server.
Use CWE-434, Projectsend vendor hub and Projectsend product page to widen CVE-2023-53980 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-11680, CVE-2021-40887 and CVE-2023-53930 for nearby disclosures in the same product family.