We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-11680

ProjectSend Unauthenticated Configuration Modification



Description

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

Reserved 2024-11-25 | Published 2024-11-26 | Updated 2024-12-06 | Assigner VulnCheck


CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA Known Exploited Vulnerability

Date added 2024-12-03 | Due date 2024-12-24

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Problem types

CWE-287 Improper Authentication

Product status

Default status
unaffected

Any version before r1720
affected

Timeline

2023-01-19:Synactiv discloses to ProjectSend
2023-05-16:ProjectSend patches the vulnerability
2024-07-19:Synactiv releases an advisory
2024-08-03:ProjectSend releases the official patch in r1720
2024-08-30:A Metasploit pull request is opened
2024-09-03:A Nuclei pull request is opened
2024-11-25:A CVE is assigned

References

github.com/...ommit/193367d937b1a59ed5b68dd4e60bd53317473744 patch

www.synacktiv.com/...rojectsend-multiple-vulnerabilities.pdf third-party-advisory exploit

github.com/.../exploits/linux/http/projectsend_unauth_rce.rb exploit

github.com/...p/vulnerabilities/projectsend-auth-bypass.yaml exploit

vulncheck.com/advisories/projectsend-bypass third-party-advisory

cve.org (CVE-2024-11680)

nvd.nist.gov (CVE-2024-11680)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-11680

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.