ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.
This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
ProjectSend Improper Authentication Vulnerability
ProjectSend ProjectSend
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
12/3/2024
https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744 ; https://nvd.nist.gov/vuln/detail/CVE-2024-11680
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
This vulnerability has a 91.70% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.
View this score breakdown or calculate a custom score
Learn how severity scores are calculated and what they mean
Best practices for deciding which vulnerabilities to address first
Essential guide to Common Vulnerabilities and Exposures
Understand how CVEs relate to underlying weakness types