CVE-2024-11680

⚠ KEVEPSS 93.5%

ProjectSend Improper Authentication Vulnerability

加入 CISA KEV 日:2024/12/3

描述

ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

受影響套件(0)

OSV 沒有提供套件對應。