CVE-2024-11680: ProjectSend Improper Authentication Vulnerability
ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.
Other sources
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ProjectSendto a version that resolves this vulnerability.Fixed in r1720 - Compensating control
If you cannot apply the ProjectSend mitigation/fix, discontinue use of ProjectSend because versions prior to r1720 are affected by an improper authentication vulnerability that allows remote unauthenticated attackers to modify configuration via crafted HTTP requests to options.php.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11680?
CVE-2024-11680 is a critical severity vulnerability that allows unauthorized modification of the application's configuration.
How do I fix CVE-2024-11680?
To fix CVE-2024-11680, update ProjectSend to the latest version beyond r1720 that addresses the vulnerability.
Who is affected by CVE-2024-11680?
Any instance of ProjectSend running versions prior to the secured update is vulnerable to CVE-2024-11680.
What type of attack does CVE-2024-11680 enable?
CVE-2024-11680 enables remote attackers to perform unauthorized actions, including creating accounts, via crafted HTTP requests.
Is authentication required to exploit CVE-2024-11680?
No, CVE-2024-11680 can be exploited by remote, unauthenticated attackers.