KEVIntel
9.8
CVSS
Critical

CVE-2024-11680

PUBLISHED

ProjectSend Unauthenticated Configuration Modification

Exploited in the wild PoC available Remote Low complexity No user interaction
Vendor
ProjectSend
Product
ProjectSend
Published
Nov 26, 2024
EPSS

Description

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

php java cisa nuclei_scanner metasploit

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2024-12-03 00:00:00 UTC · Source

Proof of concept available

Recorded 2024-12-04 18:42:43 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Dec 03, 2024

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

projectsend_unauth_rce

metasploit · Created Unknown

Metasploit module for CVE-2024-11680

D3N14LD15K/CVE-2024-11680_PoC_Exploit

github · Created 2024-12-04 18:42:43 UTC · 13 stars

This repository contains a Proof of Concept (PoC) exploit for CVE-2024-11680, a critical vulnerability in ProjectSend r1605 and older versions. The exploit targets an improper authentication flaw due Privilege Misconfiguration issues.

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Proof of Concept Exploit Available

  • Detected by Nuclei

  • Detected by Metasploit