varandinawer

1 exploit Active since Jan 2021
CVE-2020-28874 NOMISEC HIGH WORKING POC
ProjectSend < r1295 - Unauthenticated Password Reset via Invalid Token Handling
reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).
CVSS 7.5