CVE-2017-9741: ProjectSend

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLES_PREFIX in the configuration file.

Affected products

Published 2017-06-18. Last modified 2026-06-17.