CVE-2024-11680
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
91.7%
99.8th percentile
CISA KEV
Listed
Added 2024-12-03 · patch by 2024-12-24
Weakness / dates
—
Published — · modified —
Description
ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.