A critical flaw in the open-source file-sharing platform ProjectSend is being actively exploited in the wild, allowing unauthenticated attackers to take over vulnerable servers. The vulnerability, tracked as CVE-2024-11680, affects versions earlier than r1720 and stems from crafted HTTP requests to options.php that let attackers alter application configuration without logging in. Researchers reported exploitation dating back to at least September 2024, while the bug itself had been patched earlier, leaving many internet-exposed instances still vulnerable.
Successful exploitation can enable attackers to create user accounts, enable new-user registration, upload webshells, inject malicious JavaScript, and ultimately achieve remote code execution with full control of the system. Defenders were urged to upgrade immediately to ProjectSend r1720 or later and investigate for signs of compromise, including suspicious PHP files under /upload/files/, unexpected changes to homepage text, and unauthorized account or registration-setting changes.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
VulnCheck reported that exploitation of the ProjectSend vulnerability had been observed in the wild since at least September 2024. The bug could be abused to create accounts, upload webshells, inject JavaScript, and execute code remotely.
The ProjectSend vulnerability received the identifier CVE-2024-11680 in November 2024. This occurred well after the patch had already been released.
ProjectSend fixed the vulnerability affecting versions earlier than r1720 in May 2023. The flaw allowed unauthenticated attackers to change configuration and ultimately gain full control of affected systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.