CVE-2024-11680 is a critical missing-authentication vulnerability in ProjectSend versions prior to r1720. ProjectSend fails to verify that a requester is authenticated before allowing crafted HTTP requests to the options.php configuration-management endpoint. A remote unauthenticated attacker can modify application configuration, including settings that facilitate account creation, malicious file upload, and script injection.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone proof-of-concept exploit for ProjectSend CVE-2024-11680. It contains two files: a README with usage notes and one Python script, exploit.py, which is the sole executable entry point. The script is not part of a larger exploitation framework. The exploit chain is multi-stage and fully offensive rather than merely diagnostic. First, it sends a GET request to the target's /index.php to extract a CSRF token and the current installation title from the HTML response. It then abuses the vulnerable /options.php endpoint to change the installation title and re-requests /index.php to confirm the change, using that as a vulnerability check. After confirming exploitation, it again posts to /options.php to enable insecure settings: client self-registration, automatic approval, and client uploads. Next, the script registers a new client account through /register.php using randomly generated credentials and a synthetic email address. With that account context established, it uploads a PHP web shell to /includes/upload.process.php. The uploaded payload is a simple command-execution shell: it prints a fixed marker string, then runs system($_GET["cmd"]). The file is given a .phtml extension to increase the chance of server-side execution. After upload, the script attempts to derive the final public file path under /upload/files/ by combining a guessed timestamp window, the SHA-1 hash of the generated username, and the chosen filename. It probes candidate URLs until it finds one returning HTTP 200 and the expected marker string. Once found, it appends ?cmd=<urlencoded command> and performs remote command execution, printing the command output to the operator. Capabilities include unauthenticated configuration tampering, privilege weakening of the application, account creation, arbitrary file upload, web shell placement, path discovery of the uploaded shell, and arbitrary command execution on the underlying host. The code uses Python requests for HTTP session handling, regex for token/title extraction, and colorama for terminal output. Overall, this is an operational PoC with a hardcoded but functional payload, suitable for exploitation of exposed vulnerable ProjectSend instances.
This repository contains a single Metasploit module (modules/exploits/linux/http/projectsend_unauth_rce.rb) targeting ProjectSend versions r1295 through r1605. The exploit leverages an improper authorization vulnerability (CVE-2024-11680) that allows an unauthenticated attacker to achieve remote code execution. The module works by enabling user registration and disabling file extension restrictions, registering a new user, uploading a malicious PHP payload, and then triggering the payload to gain code execution. The default payload is a PHP Meterpreter reverse shell, but any PHP payload supported by Metasploit can be used. The module interacts with several HTTP endpoints on the target, including /index.php for CSRF token retrieval and vulnerability checks, /options.php for configuration changes, and /upload/files/<filename> for payload delivery and execution. The code is mature, weaponized, and ready for operational use within the Metasploit framework.
This repository provides a Bash-based Proof of Concept (PoC) exploit for CVE-2024-11680, targeting ProjectSend r1605 and earlier. The exploit demonstrates a chain of vulnerabilities: it first confirms an improper authentication flaw by modifying the application's title via a CSRF attack, then enables insecure configuration options (client registration, auto-approval, file uploads), and finally registers a new user to highlight privilege misconfiguration. The main exploit logic is contained in 'exploit.sh', which uses curl to interact with the target's web endpoints. The script is self-contained, generates random credentials for the new user, and cleans up after execution. The README.md provides detailed usage instructions and context. No hardcoded IPs or domains are present; the target URL is supplied by the user at runtime. The exploit is a functional PoC and does not provide a weaponized or post-exploitation payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Critical authentication implementation flaw in ProjectSend that allows a remote unauthenticated attacker to send crafted HTTP requests to options.php to change application configuration, create user accounts, upload webshells, inject malicious JavaScript, and ultimately achieve remote code execution and full system compromise.
A critical authentication bypass in the ProjectSend file-sharing web application that allows unauthenticated attackers to send crafted requests to options.php to change configuration, enabling actions like creating rogue accounts and uploading webshells for remote access.
Missing-authentication flaw in a file-sharing PHP product that permits unauthenticated requests to PHP library files and can enable configuration changes and code execution.
Authentication flaw allowing configuration changes, code execution, and other impacts.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.