Description
projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft a JavaScript payload in the custom assets section that will execute when other users load the affected page, enabling persistent script injection.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Mirabbas Ağalarov
References
www.exploit-db.com/exploits/51518
www.exploit-db.com/exploits/51518 (ExploitDB-51518)
www.projectsend.org/ (Official Product Webpage)
www.vulncheck.com/...s-site-scripting-via-custom-assets-page (VulnCheck Advisory: ProjectSend r1605 Stored Cross-Site Scripting via Custom Assets Page)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.