Metrics
Affected Vendors & Products
Thu, 12 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in projectsend up to r1945. This affects the function realpath of the file /import-orphans.php of the component Delete Handler. Performing a manipulation of the argument files[] results in path traversal. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | projectsend Delete import-orphans.php realpath path traversal | |
| First Time appeared |
Projectsend
Projectsend projectsend |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:projectsend:projectsend:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Projectsend
Projectsend projectsend |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-12T15:40:19.925Z
Reserved: 2026-03-12T09:07:40.791Z
Link: CVE-2026-4044
Updated: 2026-03-12T15:40:15.324Z
Status : Received
Published: 2026-03-12T16:16:11.863
Modified: 2026-03-12T16:16:11.863
Link: CVE-2026-4044
No data.
OpenCVE Enrichment
No data.