High severity7.5NVD Advisory· Published Jan 26, 2021· Updated Jul 9, 2026
CVE-2020-28874
CVE-2020-28874
Description
reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<r1295+ 1 more
- (no CPE)range: <r1295
- cpe:2.3:a:projectsend:projectsend:*:*:*:*:*:*:*:*range: <r1295
- ProjectSend/ProjectSenddescription
Patches
Vulnerability mechanics
References
3- github.com/projectsend/projectsend/commit/440204734e9a1687cb9887e1c887173d23c5a93envdPatchThird Party Advisory
- github.com/projectsend/projectsend/commits/masternvdPatchThird Party Advisory
- github.com/projectsend/projectsend/releases/tag/r1295nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.