ProjectSend Vulnerability Actively Exploited by Hackers

1 min read
Source: The Hacker News
ProjectSend Vulnerability Actively Exploited by Hackers
Photo: The Hacker News
TL;DR Summary

A critical vulnerability in the ProjectSend file-sharing application, identified as CVE-2024-11680 with a CVSS score of 9.8, is being actively exploited. The flaw, an improper authorization check, allows attackers to execute arbitrary PHP code on affected servers. Despite being patched in version r1720, only 1% of ProjectSend servers have updated, leaving many vulnerable. Exploitation began in September 2024, with attackers using exploit code to gain unauthorized access and potentially install web shells. Users are urged to update to the latest version to mitigate risks.

Share this article

Reading Insights

Total Reads

0

Unique Readers

10

Time Saved

1 min

vs 2 min read

Condensed

77%

37284 words

Want the full story? Read the original article

Read on The Hacker News