ProjectSend r561 Ultimate Cross Site Scripting / Path Disclosure

ProjectSend version r561 Ultimate suffers from cross site scripting and path disclosure vulnerabilities.