December 3 Advisory: Actively Exploited RCE Vulnerability in ProjectSend [CVE-2024-11680]
Common Information
Type Value
UUID fad37bc4-43d4-4f31-ada9-ea555d559242
Fingerprint bf21395f68b129cd
Analysis status IN_PROGRESS
Considered CTI value 0
Text language
Published Dec. 3, 2024, 9:28 p.m.
Added to db Dec. 3, 2024, 11:08 p.m.
Last updated Dec. 18, 2024, 3:08 p.m.
Headline December 3 Advisory: Actively Exploited RCE Vulnerability in ProjectSend [CVE-2024-11680]
Title December 3 Advisory: Actively Exploited RCE Vulnerability in ProjectSend [CVE-2024-11680]
Detected Hints/Tags/Attributes 29/2/26
Source URLs
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 77 Censys https://censys.io/feed 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details CVE 34
cve-2024-11680
Details Domain 1
www.projectsend.org
Details Domain 1
ksuid.new
Details Domain 10
host.services
Details Domain 660
nvd.nist.gov
Details Domain 43
vulncheck.com
Details Domain 4335
github.com
Details File 20
options.php
Details File 19
response.html
Details File 1
ckeditor.js
Details File 231
min.js
Details File 1
projectsend_unauth_rce.rb
Details File 1
synacktiv-projectsend-multiple-vulnerabilities.pdf
Details Github username 27
projectdiscovery
Details Github username 1
segmentio
Details Github username 2
projectsend
Details Github username 47
rapid7
Details sha1 2
193367d937b1a59ed5b68dd4e60bd53317473744
Details Url 1
https://www.projectsend.org
Details Url 1
https://nvd.nist.gov/vuln/detail/cve-2024-11680
Details Url 4
https://vulncheck.com/blog/projectsend-exploited-itw
Details Url 1
https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/projectsend-auth-bypass.yaml
Details Url 1
https://github.com/segmentio/ksuid
Details Url 2
https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744
Details Url 1
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/projectsend_unauth_rce.rb
Details Url 1
https://www.synacktiv.com/sites/default/files/2024-07/synacktiv-projectsend-multiple-vulnerabilities.pdf