ProjectSend Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2021-40886 - Vulnerability Database
ProjectSend Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2021-40886
Medium
Reference:
CVE-2021-40886
Title:
ProjectSend Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Overview:
Projectsend version r1295 is affected by a directory traversal vulnerability. A user with Uploader role can add value 2 for chunks parameter to bypass fileName sanitization.