CVE-2024-11680

9.8
CRITICALCVSS v3.1 Base Score
91.70%
HIGH RiskEPSS (100th percentile)
KEV

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

Published: 11/26/2024
Modified: 7/14/2026
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

ProjectSend Improper Authentication Vulnerability

Vendor / Product:

ProjectSend ProjectSend

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Due Date: 12/24/2024(OVERDUE)
Added to KEV:

12/3/2024

Notes:

https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744 ; https://nvd.nist.gov/vuln/detail/CVE-2024-11680

Vulnerability Summary

CVSS v3 Score

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

91.70%HIGH Exploitation Risk
100th percentile

This vulnerability has a 91.70% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

CWE Classification

Advertisement