← back
CVE-2024-11680criticalunder attackCWE-306

ProjectSend Unauthenticated Configuration Modification

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 92%
from disclosure to weapon8 days
Published on NVDNov 26
1st PoC+8d
metasploitJul 19
CISA KEV+7d
exploitation probability
92%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
7 public exploit(s)
Action required by CISAfederal deadline: 2024-12-24

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.