CVE-2024-11680
KEVCRITICAL 9.8EPSS 91.5%
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 91.46% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2024-12-03
- Nuclei
- critical
- Published
- 2024-11-26
- Updated
- 2026-07-14
Proof-of-concept exploits (3)
- https://www.synacktiv.com/sites/default/files/2024-07/synacktiv-projectsend-multiple-vuln…
- D3N14LD15K/CVE-2024-11680_PoC_Exploit12★ · 2025-01-31
- qucklecrabik/CVE-2024-11680