Technical Severity
CRITICAL
CVSS v3.1 Metrics
9.8
/ 10
Minimal Risk
Critical
Vector Specification
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Likelihood
EPSS Prediction
93.49
%
Predictive Probability
Percentile Rank
99.8
th
Documented as more likely to be exploited than 99.8% of known CVEs.
Detection Date
Dec 03, 2024
Remediation Due
Dec 24, 2024
CISA Catalog Active
Threat Analysis
ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.
Remediation Directive
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.