LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-11680: ProjectSend Improper Authentication Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 3, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 24, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-11680 to its Known Exploited Vulnerabilities catalog on Dec 3, 2024, with a federal patch deadline of Dec 24, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP…

CVE-2024-11680 is an improper authentication flaw in ProjectSend that lets a remote attacker with no credentials alter the application's configuration by sending crafted HTTP requests to options.php. Once configuration is changed, an attacker can create accounts, upload webshells, and inject malicious JavaScript, giving them a foothold on the server and potential access to shared files.

IT and security teams should treat this as a high-priority issue for any internet-facing or internal ProjectSend instance because successful abuse can lead directly to unauthorized access and code execution. Confirm all version and patch details against the vendor advisory before acting.

How it works

The vulnerability is classified as CWE-287 (Improper Authentication). ProjectSend fails to enforce proper authentication checks on the options.php endpoint. An unauthenticated remote attacker can therefore issue specially crafted HTTP requests that modify application settings without presenting valid credentials.

After the configuration is altered, the attacker can create new user accounts, upload web shells for persistent remote control, and embed malicious JavaScript that may execute in the browsers of legitimate users. No further authentication is required for these follow-on actions once the initial configuration change succeeds. Exact request formats and payloads are not detailed here; refer to the vendor advisory for technical confirmation.

Am I affected? How to find it in your systems

ProjectSend is typically deployed as a self-hosted web application for file sharing and collaboration, often running on Linux or Windows web servers with PHP and a database backend. It may appear on internal file-transfer portals, client extranets, or public-facing upload sites.

How to remediate

Apply the vendor-supplied update or mitigation instructions for ProjectSend as the primary remediation step. CISA directs organizations to follow the vendor guidance or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls that limit who can reach the vulnerable endpoint and what an attacker can achieve.

If your data may have been exposed

Actively exploited vulnerabilities of this class frequently lead to account takeover, webshell deployment, and data theft. If logs or other indicators suggest compromise, treat the incident as a potential breach: isolate the host, preserve forensic evidence, rotate credentials, and notify affected parties according to your incident-response plan. You can also run a free exposure scan of your email addresses to check whether they appear in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedProjectSend · ProjectSend
WeaknessCWE-287
Added to CISA KEVDec 3, 2024
Federal patch deadlineDec 24, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities