S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 17, 2025

CVE-2024-11680 Scanner

This scanner targets the registration settings and file extension whitelist endpoints in ProjectSend, allowing an attacker to bypass authorization and modify critical configurations.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-11680
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ProjectSendby ProjectSend
AFFECTED< r1720SAFE ✓≥ r1720
projectsendby projectsend
AFFECTED< r1720SAFE ✓≥ r1720
Updated Sep 10, 2026View on NVD →
Detail

ProjectSend is an open-source file sharing platform used by organizations to securely distribute files among team members and external clients. It is popular in small to medium enterprises, legal firms, and consultancy sectors for its user-friendly interface and role-based access controls. Administrators rely on it to manage permissions, control downloads, and maintain data privacy in collaborative projects.

CVE-2024-11680 is an improper access control vulnerability that arises when ProjectSend fails to enforce proper authorization checks on certain administrative functions. This flaw allows unauthenticated or low-privilege users to access and modify sensitive settings without proper validation. The vulnerability stems from insufficient server-side verification of user roles and permissions.

Specifically, the vulnerability targets the registration settings and the whitelist of allowed file extensions within ProjectSend. Attackers can exploit these endpoints to enable self-registration or permit dangerous file types like executable scripts. The vulnerable functions lack adequate access control checks, making them accessible to any user who can reach the application.

If exploited, an attacker can gain unauthorized control over file upload policies, potentially leading to remote code execution or data breaches. With a CVSS score of 9.8, this vulnerability poses a critical risk, allowing complete compromise of the application and its data. Organizations may face data loss, regulatory penalties, and reputational damage if exploited.

Solution Advice
  • Update ProjectSend to the latest patched version immediately.
  • Restrict access to the settings page using IP whitelisting or VPN.
  • Implement role-based access controls to enforce least privilege.
  • Audit user accounts and remove any unauthorized or inactive users.
  • Enable detailed logging for all configuration changes and monitor for anomalies.
  • Disable self-registration if not required for business operations.
  • Review and restrict allowed file extensions to only safe types.
  • Conduct regular security assessments to identify similar access control flaws.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

ProjectSend Access Control Scanner | S4E Free Check