Exploited Vulnerabilities Daily
🌐 English

Home › ProjectSend

CVE-2024-11680: ProjectSend ProjectSend

EPSS91.6%No. 437 of 1739 in KEV
CVE year2024listed the same year
Same vendor in KEV1
Same product1
FieldValue
VendorProjectSend
ProductProjectSend
NameProjectSend Improper Authentication Vulnerability
Added to KEV2024-12-03
US federal due date2024-12-24
Ransomware useUnknown
CWECWE-287

CISA description

ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

NVD — CVE-2024-11680

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A ProjectSend ProjectSend vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2024-12-03.