CVE-2024-11680Active Exploitation(projectsend / projectsend)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Prioritize remediation for projectsend projectsend systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

7.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-12-24. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-306

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • projectsend

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • 4 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Products
projectsend

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-02: 4PoC Mentioned / Linked · 2026-05-02: 1Exploit Tool / Code · 2026-05-02: 1Active Exploitation · 2026-05-02: 2Technical Details · 2026-05-02: 305-02
Signal classification3 categories
Active Exploitation
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets1 URL
By indicator
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2024-11680: CISA adds CVE-2024-11680: unauthenticated options.php config change in ProjectSend enables account creation, webshell uploads, malicious JS.

    Post summary

    CISA announces CVE-2024-11680, an unauthenticated configuration change in ProjectSend’s options.php that allows creation of accounts, webshell uploads, and malicious JavaScript.

    1000043
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    What happened CISA added CVE-2024-11680 to the Known Exploited Vulnerabilities (KEV) catalog on 2024-12-03, signaling observed exploitation in the wild CISA KEV. The issue is an improper authentication bug in ProjectSend that allows unauthenticated changes to application…

    Post summary

    CISA listed CVE-2024-11680 in its KEV catalog, confirming that the improper authentication flaw in ProjectSend is being actively exploited in the wild.

    1000035
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    NVD tracks the flaw as CVE-2024-11680 and maps it to CWE-287 (Improper Authentication) NVD entry. The MITRE CVE record aligns on the identifier and vulnerability class MITRE CVE. CISA set a remediation due date of 2024-12-24 for covered entities CISA KEV.

    Post summary

    The post simply reports the existence, CVE and CWE identifiers, and a CISA remediation due date, but offers no PoC, exploitation, patch, or false‑positive information.

    1000045
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2024-11680-projectsend #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The research link indicates that CVE-2024-11680 in ProjectSend has an active exploit, implying both PoC and real‑world exploitation, but lacks details on patches or technical specifics.

    0000032
    152 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprojectsendprojectsend---

Explore more