Junglewise Threat Intelligence

CVE-2024-11680: ProjectSend Improper Authentication Vulnerability

CVE-2024-11680 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-12-03

Technologies: ProjectSend. Vendors: ProjectSend.

Executive brief

ProjectSend versions prior to r1720 contain an improper authentication vulnerability in options.php. Remote, unauthenticated attackers can send crafted HTTP requests to modify the application\'s configuration, leading to account creation, webshell uploads, and remote code execution.

Affected products

  • ProjectSend ProjectSend prior to r1720

Timeline

  • 2024-11-26: disclosed: New CVE received from VulnCheck
  • 2024-12-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-12-03: advisory: Published date

Related threats