ProjectSend Vulnerability Actively Exploited by Hackers

TL;DR Summary
A critical vulnerability in the ProjectSend file-sharing application, identified as CVE-2024-11680 with a CVSS score of 9.8, is being actively exploited. The flaw, an improper authorization check, allows attackers to execute arbitrary PHP code on affected servers. Despite being patched in version r1720, only 1% of ProjectSend servers have updated, leaving many vulnerable. Exploitation began in September 2024, with attackers using exploit code to gain unauthorized access and potentially install web shells. Users are urged to update to the latest version to mitigate risks.
- Critical Flaw in ProjectSend Under Active Exploitation Against Public-Facing Servers The Hacker News
- Hackers exploit ProjectSend flaw to backdoor exposed servers BleepingComputer
- CVE Created for 18 Month-Old Flaw SC Media UK
- Malicious Actors Exploit ProjectSend Critical Vulnerability Infosecurity Magazine
- Hackers Exploiting ProjectSend Authentication Vulnerability In The Wild CybersecurityNews
Reading Insights
Total Reads
0
Unique Readers
10
Time Saved
1 min
vs 2 min read
Condensed
77%
372 → 84 words
Want the full story? Read the original article
Read on The Hacker News