Ad

CVE-2026-5624

MEDIUM CVSS 4.0: 5.3
Updated Apr 06, 2026
PHP
Parameter Value
CVSS 5.3 (MEDIUM)
Type CWE-352 (Cross-Site Request Forgery (CSRF)), CWE-862 (Missing Authorization)
Vendor PHP
Public PoC No

A security flaw has been discovered in ProjectSend r2002. This vulnerability affects unknown code of the file upload.php. Performing a manipulation results in cross-site request forgery.

The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version r2029 is able to resolve this issue.

The patch is named 2c0d25824ab571b6c219ac1a188ad9350149661b. You should upgrade the affected component.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products

n/a:projectsend