CVE-2024-11680
⚠ KEVEPSS 93.5%ProjectSend Improper Authentication Vulnerability
Added to CISA KEV: 12/3/2024
Description
ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.
Affected packages (0)
No package mapping in OSV.