Umbra Wiki cve cve/CVE-2024-11680
Back to wiki

CVE-2024-11680 — ProjectSend Improper Authentication Vulnerability

provenance: imported · CVE: CVE-2024-11680

CVE-2024-11680: ProjectSend Improper Authentication Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project ProjectSend
Product ProjectSend
Date added 2024-12-03
Due date 2024-12-24
Ransomware campaign use Unknown

Description

ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

Required action (CISA)

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Notes

https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744 ; https://nvd.nist.gov/vuln/detail/CVE-2024-11680

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-11680
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog