CRITICAL

CVE-2024-11680

Projectsend Projectsend 2024-11-26 CVSS v3.1
CVSS
9.8
KEV

Description

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

Summary dbcve.org

ProjectSend versions prior to r1720 contain an improper authentication vulnerability in options.php that allows remote, unauthenticated attackers to send crafted HTTP requests and modify application configuration. This enables account creation, webshell upload, and malicious JavaScript injection.

Mitigation

Upgrade to ProjectSend r1720 or later to patch the authentication bypass. If immediate upgrade is not feasible, implement network-level access controls to restrict access to options.php from untrusted sources.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

91.7%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE