
ProjectSend Vulnerability Actively Exploited by Hackers
A critical vulnerability in the ProjectSend file-sharing application, identified as CVE-2024-11680 with a CVSS score of 9.8, is being actively exploited. The flaw, an improper authorization check, allows attackers to execute arbitrary PHP code on affected servers. Despite being patched in version r1720, only 1% of ProjectSend servers have updated, leaving many vulnerable. Exploitation began in September 2024, with attackers using exploit code to gain unauthorized access and potentially install web shells. Users are urged to update to the latest version to mitigate risks.