CVE-2023-53930
HIGHProjectSend r1605 - Info Disclosure
Title source: llmDescription
ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changing the 'id' parameter in the download request to process.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Mirabbas Ağalarov · textwebappsphp
https://www.exploit-db.com/exploits/51400
Scores
CVSS v3
7.5
EPSS
0.0006
EPSS Percentile
19.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-639
Status
published
Products (2)
projectsend/projectsend
r1605
projectSend/projectSend
r1605
Published
Dec 17, 2025
Tracked Since
Feb 18, 2026