CVE-2024-11680
ProjectSend
Published 26 Nov 2024 · updated 14 Jul 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Dec 2024, with a remediation deadline of 24 Dec 2024 for US federal agencies.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.
References
- github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/projectsend-auth-bypass.yaml · Broken Link, Third Party Advisory
- github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744 · Patch
- github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/projectsend_unauth_rce.rb · Exploit
- vulncheck.com/advisories/projectsend-bypass · Third Party Advisory
- www.synacktiv.com/sites/default/files/2024-07/synacktiv-projectsend-multiple-vulnerabilities.pdf · Mitigation, Technical Description, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-11680 · US Government Resource