No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 12 Mar 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in projectsend up to r1945. The affected element is an unknown function of the component AJAX Endpoints. The manipulation leads to missing authorization. The attack can be initiated remotely. The identifier of the patch is 35dfd6f08f7d517709c77ee73e57367141107e6b. To fix this issue, it is recommended to deploy a patch. | |
| Title | projectsend AJAX Endpoints authorization | |
| First Time appeared |
Projectsend
Projectsend projectsend |
|
| Weaknesses | CWE-862 CWE-863 |
|
| CPEs | cpe:2.3:a:projectsend:projectsend:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Projectsend
Projectsend projectsend |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-12T03:02:08.383Z
Reserved: 2026-03-11T14:20:26.569Z
Link: CVE-2026-3977
No data.
Status : Received
Published: 2026-03-12T04:16:39.867
Modified: 2026-03-12T04:16:39.867
Link: CVE-2026-3977
No data.
OpenCVE Enrichment
No data.