CVE-2020-28874: ProjectSend

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).

Affected products

Published 2021-01-26. Last modified 2026-07-09.