This Metasploit module exploits an improper authorization vulnerability in ProjectSend versions r1295 through r1605. The vulnerability allows an unauthenticated attacker to obtain remote code execution by enabling user registration, disabling the whitelist of allowed file extensions, and uploading a malicious PHP file to the server.
🛡️ VERIFIED CYBER INTELLIGENCE ID: #2428969
💾 ProjectSend R1605 Unauthenticated Remote Code Execution
⏱️ vor 612d 4h (22.11.2024 um 16:42 Uhr) 📂 💾 IT Security Tools 📡 Feed 🔗 Quelle: packetstormsecurity.com