CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2024-11680

KEV Critical · CVSS 9.8

ProjectSend — Improper Authentication / Authentication Bypass leading to Unauthenticated RCE

CVSS
9.8
nvd
EPSS
KEV
Listed
2024-12-03
Class
oss containerizable
CWE-306, CWE-306

Description

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

Search profile — drives PoC discovery

Symbols options.phpprojectsend_unauth_rce.rbprojectsend-auth-bypass.yamlr1720193367d937b1a59ed5b68dd4e60bd53317473744
Keywords CVE-2024-11680ProjectSendauthentication bypassoptions.phpunauthenticated RCEwebshell uploadimproper authenticationProjectSend r1720ProjectSend exploitProjectSend PoC
Versions: < r1720

Ranked PoCs (17) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z