Security
Loading…

CVE-2024-11680

CRITICALCVSS 9.8Known Exploited
Description

ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

Timeline
Published:November 26th, 2024 10:15 AM
Last modified:July 14th, 2026 11:17 PM
Added to KEV:December 3rd, 2024
CVSS Scoring

CVSS v3: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

projectsend

Products

projectsend
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute