EXPOSURES › CVE-2024-11680
CVE-2024-11680
HIGH ⌖ ON CISA KEV · EXPLOITEDProjectSend allows remote attackers to modify configuration, create accounts, and upload webshells via unauthenticated HTTP requests to options.php.
This improper authentication flaw enables attackers to bypass security controls and deploy webshells, directly threatening DIB systems that rely on ProjectSend for secure file transfers. The vulnerability is actively exploited in the wild and allows remote code execution through webshell deployment, creating a critical supply-chain risk for organizations using the software.
Shame score — Active exploitation of a critical authentication bypass that enables remote code execution and webshell deployment without requiring user credentials.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.