Critical severity9.8CISA KEVNVD Advisory· Published Nov 26, 2024· Updated Jul 14, 2026
CVE-2024-11680
CVE-2024-11680
Description
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:projectsend:projectsend:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:projectsend:projectsend:*:*:*:*:*:*:*:*range: <r1720
- (no CPE)range: <r1720
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
6- github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744nvdPatch
- github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/projectsend_unauth_rce.rbnvdExploit
- github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/projectsend-auth-bypass.yamlnvdBroken LinkThird Party Advisory
- vulncheck.com/advisories/projectsend-bypassnvdThird Party Advisory
- www.synacktiv.com/sites/default/files/2024-07/synacktiv-projectsend-multiple-vulnerabilities.pdfnvdMitigationTechnical DescriptionThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.