A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2024-11680

ProjectSend Improper Authentication Vulnerability

Published
2024-12-03
Modified
2026-07-31
Sources
cisa-kev

Summary

ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.