ProjectSend Unrestricted Upload of File with Dangerous Type Vulnerability - CVE-2019-11378
An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files../ directory traversal. It is possible for users to read arbitrary files and (potentially) access the supporting database delete arbitrary files access user passwords or run arbitrary code.