CVE CVE

CVE-2024-11680

CISA Known Exploited Vulnerability (KEV)

ProjectSend Improper Authentication Vulnerability

December 3, 2024

December 24, 2024

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application’s configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

Weakness Enumeration

CWE-ID CWE Name

CWE-287
Improper Authentication

CWE-863
Incorrect Authorization

Known Affected Software Configurations


cpe:2.3:a:projectsend:projectsend:r1335:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r1415:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r1420:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r1584:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r1605:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r1295:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r1270:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:582:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:1053:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:756:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:754:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:753:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:559:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r609:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r582:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r572:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r571:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r561:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r514:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r412:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r405:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r375:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r1053:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r756:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r754:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r753:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r559:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:r1070:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:1070:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:100:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:102:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:105:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:110:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:155:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:156:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:157:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:161:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:180:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:335:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:375:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:405:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:412:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:514:*:*:*:*:*:*:*

cpe:2.3:a:projectsend:projectsend:561:*:*:*:*:*:*:*

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
9.8
Severity:

CRITICAL

Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2

Not defined