CVE-2024-11680

⚠ KEVEPSS 93.5%

ProjectSend Improper Authentication Vulnerability

Added to CISA KEV: 12/3/2024

Description

ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

Affected packages (0)

No package mapping in OSV.