{"cvss":9.8,"datePublished":"2024-12-03","dateUpdated":"2024-12-03","description":"ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.","dueDate":"2024-12-24","id":"CVE-2024-11680","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Unknown","notes":"https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744 ; https://nvd.nist.gov/vuln/detail/CVE-2024-11680","product":"ProjectSend","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","severity":"CRITICAL","source":"cisa_known_exploited","title":"ProjectSend Improper Authentication Vulnerability","vendor":"ProjectSend"}