CVE-2024-11680 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 91.7% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2024-12-24.
Description
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 91.7% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-306 |
| On CISA KEV | yes — remediate by 2024-12-24 |
| Public exploit | none known |
| Published | 2024-11-26 |
| Last modified | 2026-07-14 |
CISA KEV
| Name | ProjectSend Improper Authentication Vulnerability |
|---|---|
| Added | 2024-12-03 |
| Due | 2024-12-24 |
| Vendor / product | ProjectSend / ProjectSend |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| projectsend | projectsend |
References
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/projectsend-auth-bypass.yaml
- https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744
- https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/projectsend_unauth_rce.rb
- https://vulncheck.com/advisories/projectsend-bypass
- https://www.synacktiv.com/sites/default/files/2024-07/synacktiv-projectsend-multiple-vulnerabilities.pdf
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-11680
→ the Explorer · watch your stack · NVD