{"api_version":"1","generated_at":"2026-07-23T12:54:19+00:00","cve":"CVE-2024-11680","urls":{"html":"https://cve.report/CVE-2024-11680","api":"https://cve.report/api/cve/CVE-2024-11680.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2024-11680","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2024-11680"},"summary":{"title":"ProjectSend Unauthenticated Configuration Modification","description":"ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.","state":"PUBLISHED","assigner":"VulnCheck","published_at":"2024-11-26 10:15:04","updated_at":"2026-07-14 23:17:13"},"problem_types":["CWE-306","CWE-306 CWE-306 Missing Authentication for Critical Function"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"disclosure@vulncheck.com","type":"Secondary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/projectsend_unauth_rce.rb","name":"https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/projectsend_unauth_rce.rb","refsource":"disclosure@vulncheck.com","tags":["Exploit"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.synacktiv.com/sites/default/files/2024-07/synacktiv-projectsend-multiple-vulnerabilities.pdf","name":"https://www.synacktiv.com/sites/default/files/2024-07/synacktiv-projectsend-multiple-vulnerabilities.pdf","refsource":"disclosure@vulncheck.com","tags":["Mitigation","Technical Description","Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-11680","name":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-11680","refsource":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vulncheck.com/advisories/projectsend-bypass","name":"https://vulncheck.com/advisories/projectsend-bypass","refsource":"disclosure@vulncheck.com","tags":["Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744","name":"https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744","refsource":"disclosure@vulncheck.com","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/projectsend-auth-bypass.yaml","name":"https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/projectsend-auth-bypass.yaml","refsource":"disclosure@vulncheck.com","tags":["Broken Link","Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-11680","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-11680","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"ProjectSend","product":"ProjectSend","version":"affected r1720 custom","platforms":[]},{"source":"ADP","vendor":"projectsend","product":"projectsend","version":"affected r1720 custom","platforms":[]}],"timeline":[{"source":"CNA","time":"2023-01-19T05:00:00.000Z","lang":"en","value":"Synactiv discloses to ProjectSend"},{"source":"CNA","time":"2023-05-16T04:00:00.000Z","lang":"en","value":"ProjectSend patches the vulnerability"},{"source":"CNA","time":"2024-07-19T04:00:00.000Z","lang":"en","value":"Synactiv releases an advisory"},{"source":"CNA","time":"2024-08-03T04:00:00.000Z","lang":"en","value":"ProjectSend releases the official patch in r1720"},{"source":"CNA","time":"2024-08-30T04:00:00.000Z","lang":"en","value":"A Metasploit pull request is opened"},{"source":"CNA","time":"2024-09-03T04:00:00.000Z","lang":"en","value":"A Nuclei pull request is opened"},{"source":"CNA","time":"2024-11-25T05:00:00.000Z","lang":"en","value":"A CVE is assigned"},{"source":"ADP","time":"2024-12-03T00:00:00.000Z","lang":"en","value":"CVE-2024-11680 added to CISA KEV"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2024","cve_id":"11680","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"projectsend","cpe5":"projectsend","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2024","cve_id":"11680","cve":"CVE-2024-11680","vendorProject":"ProjectSend","product":"ProjectSend","vulnerabilityName":"ProjectSend Improper Authentication Vulnerability","dateAdded":"2024-12-03","shortDescription":"ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2024-12-24","knownRansomwareCampaignUse":"Unknown","notes":"https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744 ; https://nvd.nist.gov/vuln/detail/CVE-2024-11680","cwes":"CWE-287","catalogVersion":"2026.07.22","updated_at":"2026-07-22 20:07:15"},"epss":{"cve_year":"2024","cve_id":"11680","cve":"CVE-2024-11680","epss":"0.915590000","percentile":"0.998030000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:32"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"affected":[{"cpes":["cpe:2.3:a:projectsend:projectsend:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","product":"projectsend","vendor":"projectsend","versions":[{"lessThan":"r1720","status":"affected","version":"0","versionType":"custom"}]}],"metrics":[{"other":{"content":{"id":"CVE-2024-11680","options":[{"Exploitation":"active"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2024-12-06T04:55:29.126869Z","version":"2.0.3"},"type":"ssvc"}},{"other":{"content":{"dateAdded":"2024-12-03","reference":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-11680"},"type":"kev"}}],"providerMetadata":{"dateUpdated":"2025-10-21T22:55:35.287Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"references":[{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-11680"}],"timeline":[{"lang":"en","time":"2024-12-03T00:00:00.000Z","value":"CVE-2024-11680 added to CISA KEV"}],"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","packageURL":"pkg:github/projectsend/projectsend","product":"ProjectSend","programFiles":["options.php"],"repo":"https://github.com/projectsend/projectsend","vendor":"ProjectSend","versions":[{"lessThan":"r1720","status":"affected","version":"0","versionType":"custom"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:projectsend:projectsend:*:*:*:*:*:*:*:*","versionEndExcluding":"r1720","versionStartIncluding":"0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"OR"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to <code>options.php</code>, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.<br>"}],"value":"ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript."}],"impacts":[{"capecId":"CAPEC-114","descriptions":[{"lang":"en","value":"CAPEC-114 Authentication Abuse"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-306","description":"CWE-306 Missing Authentication for Critical Function","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-14T22:54:33.035Z","orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck"},"references":[{"tags":["patch"],"url":"https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744"},{"tags":["third-party-advisory","exploit"],"url":"https://www.synacktiv.com/sites/default/files/2024-07/synacktiv-projectsend-multiple-vulnerabilities.pdf"},{"tags":["exploit"],"url":"https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/projectsend_unauth_rce.rb"},{"tags":["exploit"],"url":"https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/projectsend-auth-bypass.yaml"},{"tags":["third-party-advisory"],"url":"https://vulncheck.com/advisories/projectsend-bypass"}],"source":{"discovery":"EXTERNAL"},"tags":["x_known-exploited-vulnerability"],"timeline":[{"lang":"en","time":"2023-01-19T05:00:00.000Z","value":"Synactiv discloses to ProjectSend"},{"lang":"en","time":"2023-05-16T04:00:00.000Z","value":"ProjectSend patches the vulnerability"},{"lang":"en","time":"2024-07-19T04:00:00.000Z","value":"Synactiv releases an advisory"},{"lang":"en","time":"2024-08-03T04:00:00.000Z","value":"ProjectSend releases the official patch in r1720"},{"lang":"en","time":"2024-08-30T04:00:00.000Z","value":"A Metasploit pull request is opened"},{"lang":"en","time":"2024-09-03T04:00:00.000Z","value":"A Nuclei pull request is opened"},{"lang":"en","time":"2024-11-25T05:00:00.000Z","value":"A CVE is assigned"}],"title":"ProjectSend Unauthenticated Configuration Modification","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","assignerShortName":"VulnCheck","cveId":"CVE-2024-11680","datePublished":"2024-11-26T09:55:23.588Z","dateReserved":"2024-11-25T15:03:30.218Z","dateUpdated":"2026-07-14T22:54:33.035Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2024-11-26 10:15:04","lastModifiedDate":"2026-07-14 23:17:13","problem_types":["CWE-306","CWE-306 CWE-306 Missing Authentication for Critical Function"],"metrics":{"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-06T04:55:29.126869Z","id":"CVE-2024-11680","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:projectsend:projectsend:*:*:*:*:*:*:*:*","versionEndExcluding":"r1720","matchCriteriaId":"7595D81C-8332-4FF5-A6B6-DF6203DEF6A5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2024","CveId":"11680","Ordinal":"1","Title":"ProjectSend Unauthenticated Configuration Modification","CVE":"CVE-2024-11680","Year":"2024"},"notes":[{"CveYear":"2024","CveId":"11680","Ordinal":"1","NoteData":"ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.","Type":"Description","Title":"ProjectSend Unauthenticated Configuration Modification"}]}}}