CVE-2024-11680
KEV Critical · CVSS 9.8ProjectSend — Improper Authentication / Authentication Bypass leading to Unauthenticated RCE
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- Listed
- 2024-12-03
- Class
- oss containerizable
- CWE-306, CWE-306
Description
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.
Search profile — drives PoC discovery
Ranked PoCs (17) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 0
- ★ 0
- ★ 11
- ★ 012442RF/POC needs reviewtrickest
- ★ 0DMW11525708/wiki needs reviewtrickest
- ★ 0Lern0n/Lernon-POC needs reviewtrickest
- ★ 0Linxloop/fork_POC needs reviewtrickest
- ★ 0eeeeeeeeee-code/POC needs reviewtrickest
- ★ 0fkie-cad/nvd-json-data-feeds needs reviewtrickest
- ★ 0greenberglinken/2023hvv_1 needs reviewtrickest
- ★ 0iemotion/POC needs reviewtrickest
- ★ 0laoa1573/wy876 needs reviewtrickest
- ★ 0oLy0/Vulnerability needs reviewtrickest
- ★ 0packetinside/CISA_BOT needs reviewtrickest
- ★ 0
- ★ 0ums91/CISA_BOT needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/projectsend-auth-bypass.yaml
- https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744
- https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/projectsend_unauth_rce.rb
- https://vulncheck.com/advisories/projectsend-bypass
- https://www.synacktiv.com/sites/default/files/2024-07/synacktiv-projectsend-multiple-vulnerabilities.pdf
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-11680
Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z