CVE-2020-28874: ProjectSend
High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.
reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).
Affected products
- ProjectSend ProjectSend: before r1295 (fixed in r1295)
Published 2021-01-26. Last modified 2026-07-09.