CVE-2024-11680 is a critical improper authentication vulnerability affecting ProjectSend versions prior to r1720. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, leading to unauthorized modification of application configurations. This allows for account creation, webshell uploads, and malicious JavaScript embedding, resulting in a CVSS score of 9.8 (CRITICAL) with full confidentiality, integrity, and availability impact. The vulnerability is actively exploited in the wild, has publicly available exploit modules (e.g., Metasploit), and has garnered significant community and media attention, including CISA warnings.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< r1720CPE matchmatch criteria | cpe:2.3:a:projectsend:projectsend:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.