FAIL › dossier
ProjectSend
VENDOR· dossier confidence 50%
ProjectSend is a file-sharing application with a critical security flaw allowing unauthenticated attackers to execute remote code and create accounts via improper authentication in options.php.
PROFILE
Categoryfile-sharing softwareWhat they doProjectSend is a PHP-based file-sharing application that allows users to upload, manage, and share files via a web interface.
SECURITY POSTURE
The vendor has a critical vulnerability in its authentication mechanism that allows unauthenticated remote code execution and account creation, indicating a severe lapse in access control and input validation.
Notable failures
- CVE-2024-11680: Unauthenticated RCE via options.php
- CVE-2024-11680: Improper authentication allowing account creation
- CVE-2024-11680: Unauthenticated webshell upload
Patterns: unauthenticated remote code execution; improper authentication bypass
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-12-03 | CVE-2024-11680 | high | ProjectSend allows remote attackers to modify configuration, create accounts, and upload webshells via unauthenticated HTTP requests to options.php. |
| 2024-12-03 | CVE-2024-11680 | high | ProjectSend allows remote attackers to modify configuration, create accounts, and upload webshells via unauthenticated HTTP requests to options.php. |
| 2024-11-26 | CVE-2024-11680 | critical | CVE-2024-11680: ProjectSend versions prior to r1720 are affected by an improper authentication v |
| 2024-11-26 | CVE-2024-11680 | critical | CVE-2024-11680: ProjectSend versions prior to r1720 are affected by an improper authentication v |
Open questions: ProjectSend's official website URL · ProjectSend's founding year · ProjectSend's headquarters location · ProjectSend's organizational size
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-28 04:06:49.963196+00:00