Executive brief
ProjectSend versions prior to r1720 contain an improper authentication vulnerability in options.php. Remote, unauthenticated attackers can send crafted HTTP requests to modify the application\'s configuration, leading to account creation, webshell uploads, and remote code execution.
Affected products
- ProjectSend ProjectSend prior to r1720
Timeline
- 2024-11-26: disclosed: New CVE received from VulnCheck
- 2024-12-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-12-03: advisory: Published date