Skip to content
COOEY

EXPOSURES › CVE-2024-11680

CVE-2024-11680

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-12-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-11680 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatchedrcesupply-chain

ProjectSend allows remote attackers to modify configuration, create accounts, and upload webshells via unauthenticated HTTP requests to options.php.

This improper authentication flaw enables attackers to bypass security controls and deploy webshells, directly threatening DIB systems that rely on ProjectSend for secure file transfers. The vulnerability is actively exploited in the wild and allows remote code execution through webshell deployment, creating a critical supply-chain risk for organizations using the software.

Shame score — Active exploitation of a critical authentication bypass that enables remote code execution and webshell deployment without requiring user credentials.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.