CVE-2024-11680
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- ProjectSend Improper Authentication Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 92% (אחוזון 100) נכון ל-26/7/2026
- CWE
- CWE-306
מוצרים מושפעים
projectsend: projectsend
קישורים
- https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60b… Patch
- https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/li… Exploit
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabil… Broken LinkThird Party Advisory
- https://vulncheck.com/advisories/projectsend-bypass Third Party Advisory
- https://www.synacktiv.com/sites/default/files/2024-07/synacktiv-projectsend-mu… MitigationTechnical DescriptionThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource