← Back

CVE-2024-11680

Published: Nov 26, 2024Modified: Jul 14, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

Affected (1)

1 product
Projectsend
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before r1720

Timeline

No history available yet.