CVE-2017-9741: ProjectSend
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLES_PREFIX in the configuration file.
Affected products
- ProjectSend ProjectSend: version r754 only
Published 2017-06-18. Last modified 2026-06-17.