Files
CVEs-PoC/2020/CVE-2020-28874.md
T
2024-05-25 21:48:12 +02:00

786 B

CVE-2020-28874

Description

reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).

POC

Reference

No PoCs from references.

Github