Skip to content
COOEY

FAIL › dossier

ProjectSend

VENDOR

· dossier confidence 50%

ProjectSend is a file-sharing application with a critical security flaw allowing unauthenticated attackers to execute remote code and create accounts via improper authentication in options.php.

PROFILE
Categoryfile-sharing softwareWhat they doProjectSend is a PHP-based file-sharing application that allows users to upload, manage, and share files via a web interface.
SECURITY POSTURE

The vendor has a critical vulnerability in its authentication mechanism that allows unauthenticated remote code execution and account creation, indicating a severe lapse in access control and input validation.

Notable failures
  • CVE-2024-11680: Unauthenticated RCE via options.php
  • CVE-2024-11680: Improper authentication allowing account creation
  • CVE-2024-11680: Unauthenticated webshell upload
Patterns: unauthenticated remote code execution; improper authentication bypass
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2024-12-03 CVE-2024-11680 high ProjectSend allows remote attackers to modify configuration, create accounts, and upload webshells via unauthenticated HTTP requests to options.php.
2024-12-03 CVE-2024-11680 high ProjectSend allows remote attackers to modify configuration, create accounts, and upload webshells via unauthenticated HTTP requests to options.php.
2024-11-26 CVE-2024-11680 critical CVE-2024-11680: ProjectSend versions prior to r1720 are affected by an improper authentication v
2024-11-26 CVE-2024-11680 critical CVE-2024-11680: ProjectSend versions prior to r1720 are affected by an improper authentication v
Open questions: ProjectSend's official website URL · ProjectSend's founding year · ProjectSend's headquarters location · ProjectSend's organizational size
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-28 04:06:49.963196+00:00