December 3 Advisory: Actively Exploited RCE Vulnerability in ProjectSend [CVE-2024-11680]
Tags
country: | United States Of America |
attack-pattern: | Data Exploits - T1587.004 Exploits - T1588.005 Javascript - T1059.007 Software - T1592.002 Vulnerabilities - T1588.006 |
Common Information
Type | Value |
---|---|
UUID | fad37bc4-43d4-4f31-ada9-ea555d559242 |
Fingerprint | bf21395f68b129cd |
Analysis status | IN_PROGRESS |
Considered CTI value | 0 |
Text language | |
Published | Dec. 3, 2024, 9:28 p.m. |
Added to db | Dec. 3, 2024, 11:08 p.m. |
Last updated | Dec. 18, 2024, 3:08 p.m. |
Headline | December 3 Advisory: Actively Exploited RCE Vulnerability in ProjectSend [CVE-2024-11680] |
Title | December 3 Advisory: Actively Exploited RCE Vulnerability in ProjectSend [CVE-2024-11680] |
Detected Hints/Tags/Attributes | 29/2/26 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://censys.com/cve-2024-11680/ |
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 77 | ✔ | Censys | https://censys.io/feed | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | CVE | 34 | cve-2024-11680 |
|
Details | Domain | 1 | www.projectsend.org |
|
Details | Domain | 1 | ksuid.new |
|
Details | Domain | 10 | host.services |
|
Details | Domain | 660 | nvd.nist.gov |
|
Details | Domain | 43 | vulncheck.com |
|
Details | Domain | 4335 | github.com |
|
Details | File | 20 | options.php |
|
Details | File | 19 | response.html |
|
Details | File | 1 | ckeditor.js |
|
Details | File | 231 | min.js |
|
Details | File | 1 | projectsend_unauth_rce.rb |
|
Details | File | 1 | synacktiv-projectsend-multiple-vulnerabilities.pdf |
|
Details | Github username | 27 | projectdiscovery |
|
Details | Github username | 1 | segmentio |
|
Details | Github username | 2 | projectsend |
|
Details | Github username | 47 | rapid7 |
|
Details | sha1 | 2 | 193367d937b1a59ed5b68dd4e60bd53317473744 |
|
Details | Url | 1 | https://www.projectsend.org |
|
Details | Url | 1 | https://nvd.nist.gov/vuln/detail/cve-2024-11680 |
|
Details | Url | 4 | https://vulncheck.com/blog/projectsend-exploited-itw |
|
Details | Url | 1 | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/projectsend-auth-bypass.yaml |
|
Details | Url | 1 | https://github.com/segmentio/ksuid |
|
Details | Url | 2 | https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744 |
|
Details | Url | 1 | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/projectsend_unauth_rce.rb |
|
Details | Url | 1 | https://www.synacktiv.com/sites/default/files/2024-07/synacktiv-projectsend-multiple-vulnerabilities.pdf |