PT-2025-47065 · Unknown · Projectsend

·

CVE-2025-13232

·

Published

2025-11-16

·

Updated

2025-11-16

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ProjectSend versions prior to r1945
Description A cross-site scripting issue exists in ProjectSend up to version r1720. The flaw is located within the File Editor/Custom Download Aliases component and involves an unknown function. This manipulation allows for remote execution of cross-site scripting. The exploit has been published.
Recommendations Upgrade to version r1945 to address this issue.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13232

Affected Products

Projectsend