VYPR
High severity7.5NVD Advisory· Published Jan 26, 2021· Updated Jul 9, 2026

CVE-2020-28874

CVE-2020-28874

Description

reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Projectsend/Projectsendllm-fuzzy2 versions
    <r1295+ 1 more
    • (no CPE)range: <r1295
    • cpe:2.3:a:projectsend:projectsend:*:*:*:*:*:*:*:*range: <r1295
  • ProjectSend/ProjectSenddescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.