Security Advisory

CVE-2016-10733

9.8
CRITICAL

Vulnerability Description

ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.
Published Date October 29, 2018
Official Source NIST NVD Advisory