CVE-2023-53930

HIGH

ProjectSend r1605 - Info Disclosure

Title source: llm

Description

ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changing the 'id' parameter in the download request to process.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Mirabbas Ağalarov · textwebappsphp
https://www.exploit-db.com/exploits/51400

Scores

CVSS v3 7.5
EPSS 0.0006
EPSS Percentile 19.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-639
Status published
Products (2)
projectsend/projectsend r1605
projectSend/projectSend r1605
Published Dec 17, 2025
Tracked Since Feb 18, 2026