A security vulnerability has been detected in projectsend up to r1945. The affected element is an unknown function of the component AJAX Endpoints. The manipulation leads to missing authorization. The attack can be initiated remotely. The identifier of the patch is 35dfd6f08f7d517709c77ee73e57367141107e6b. To fix this issue, it is recommended to deploy a patch.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Mar 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in projectsend up to r1945. The affected element is an unknown function of the component AJAX Endpoints. The manipulation leads to missing authorization. The attack can be initiated remotely. The identifier of the patch is 35dfd6f08f7d517709c77ee73e57367141107e6b. To fix this issue, it is recommended to deploy a patch. | |
| Title | projectsend AJAX Endpoints authorization | |
| First Time appeared |
Projectsend
Projectsend projectsend |
|
| Weaknesses | CWE-862 CWE-863 |
|
| CPEs | cpe:2.3:a:projectsend:projectsend:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Projectsend
Projectsend projectsend |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-12T03:02:08.383Z
Reserved: 2026-03-11T14:20:26.569Z
Link: CVE-2026-3977
No data.
Status : Received
Published: 2026-03-12T04:16:39.867
Modified: 2026-03-12T04:16:39.867
Link: CVE-2026-3977
No data.
OpenCVE Enrichment
No data.