PT-2024-8801 · Unknown · Projectsend

Florent Sicchio

+1

·

Published

2024-11-26

·

Updated

2026-05-02

·

CVE-2024-11680

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ProjectSend versions prior to r1720
Description An improper authentication issue exists where certain PHP pages perform authorization checks only after the rest of the code has already executed, allowing unauthenticated users to perform privileged operations. Remote attackers can exploit this by sending crafted HTTP requests to the 'options.php' endpoint. This allows unauthorized modification of the application configuration, enabling attackers to create rogue accounts, upload webshells, and embed malicious JavaScript to execute arbitrary PHP code on the server. Approximately 4,000 instances of the software are available on the internet, and the flaw has been actively exploited in the wild, with attackers altering system settings to enable user registration and maintain control over compromised servers. The vulnerable parameters include csrf token and section.
Recommendations Update to version r1720 or later. As a temporary workaround, block all POST requests to the 'options.php' endpoint. Alternatively, restrict all POST requests that contain the csrf token and section parameters in the request body.

Exploit

Fix

Incorrect Authorization

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-10433
CVE-2024-11680

Affected Products

Projectsend