ProjectSend Unauthenticated Configuration Modification
Summary
| CVE | CVE-2024-11680 |
|---|---|
| State | PUBLISHED |
| Assigner | VulnCheck |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-11-26 10:15:04 UTC |
| Updated | 2026-07-14 23:17:13 UTC |
| Description | ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.915590000 probability, percentile 0.998030000 (date 2026-07-22)
CISA KEV: Listed on 2024-12-03; due 2024-12-24; ransomware use Unknown
Problem Types: CWE-306 | CWE-306 CWE-306 Missing Authentication for Critical Function
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA Known Exploited Vulnerability
| Vendor | ProjectSend |
|---|---|
| Product | ProjectSend |
| Name | ProjectSend Improper Authentication Vulnerability |
| Required Action | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
| Notes | https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744 ; https://nvd.nist.gov/vuln/detail/CVE-2024-11680 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Projectsend | Projectsend | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | ProjectSend | ProjectSend | affected r1720 custom | Not specified |
| ADP | Projectsend | Projectsend | affected r1720 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linu... | [email protected] | github.com | Exploit |
| www.synacktiv.com/sites/default/files/2024-07/synacktiv-projectsend-multiple-vu... | [email protected] | www.synacktiv.com | Mitigation, Technical Description, Third Party Advisory |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| vulncheck.com/advisories/projectsend-bypass | [email protected] | vulncheck.com | Third Party Advisory |
| github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd5... | [email protected] | github.com | Patch |
| github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilit... | [email protected] | github.com | Broken Link, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2023-01-19T05:00:00.000Z | Synactiv discloses to ProjectSend |
| CNA | 2023-05-16T04:00:00.000Z | ProjectSend patches the vulnerability |
| CNA | 2024-07-19T04:00:00.000Z | Synactiv releases an advisory |
| CNA | 2024-08-03T04:00:00.000Z | ProjectSend releases the official patch in r1720 |
| CNA | 2024-08-30T04:00:00.000Z | A Metasploit pull request is opened |
| CNA | 2024-09-03T04:00:00.000Z | A Nuclei pull request is opened |
| CNA | 2024-11-25T05:00:00.000Z | A CVE is assigned |
| ADP | 2024-12-03T00:00:00.000Z | CVE-2024-11680 added to CISA KEV |
There are currently no legacy QID mappings associated with this CVE.