ProjectSend < r1720 Improper Authorization

critical Web App Scanning Plugin ID 114977

Synopsis

ProjectSend < r1720 Improper Authorization

Description

ProjectSend version prior to r1720 is affected by an Improper Authorization vulnerability. An unauthenticated attacker can exploit this issue to access sensitive information and perform unauthorized actions within the application.

Solution

Upgrade to ProjectSend version r1720 or later.

See Also

https://github.com/projectsend/projectsend

https://www.projectsend.org/

https://www.synacktiv.com/sites/default/files/2024-07/synacktiv-projectsend-multiple-vulnerabilities.pdf

Plugin Details

Severity: Critical

ID: 114977

Type: remote

Published: 10/3/2025

Updated: 10/3/2025

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: High

Score: 8.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2024-11680

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS Score Source: CVE-2024-11680

Vulnerability Information

CPE: cpe:2.3:a:projectsend:projectsend:*:*:*:*:*:*:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/3/2024

Vulnerability Publication Date: 11/25/2024

CISA Known Exploited Vulnerability Due Dates: 12/24/2024

Reference Information

CVE: CVE-2024-11680