CVE-2024-11680

CVE Published 2024-11-26
Related CWE(s) CWE-863: Incorrect Authorization, CWE-287: Improper Authentication
Related Vendor(s) projectsend
Related Product(s) projectsend
Exploitation Reported (CISA KEV) 2024-12-03
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References