ProjectSend r754 Insecure Direct Object Reference / Authenticaton Bypass

ProjectSend r754 suffers from authentication bypass and insecure direct object reference vulnerabilities.