CyberSec.Space Logo
返回 CVE 浏览器

CVE-2024-11680

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score79.8830%
EPSS Percentile89.42th
Published2024-11-26
Last Modified2026-07-14
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

Affected Platforms (CPE)

📦
Projectsend

Projectsend

< r1720

References & Advisories

相关漏洞威胁