← Browse

CVE-2024-11680

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
91.7%
99.8th percentile
CISA KEV
Listed
Added 2024-12-03 · patch by 2024-12-24
Weakness / dates
Published — · modified —

Description

ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

Official: NVD · CVE.org