Cyber Security News

Hackers Exploiting ProjectSend Authentication Vulnerability In The Wild

Hackers are actively exploiting a critical authentication vulnerability in ProjectSend, a popular open-source file-sharing web application.

The vulnerability, now identified as CVE-2024-11680, allows remote, unauthenticated attackers to bypass authentication and modify the application’s configuration, potentially leading to unauthorized account creation, webshell uploads, and malicious JavaScript injection.

Despite the patch being available since May 16, 2023, the CVE was only assigned on November 26, 2024, leaving many systems exposed for over a year.

The delay in CVE assignment is particularly notable given that Rapid7, a CVE Numbering Authority, had already published a Metasploit module for this vulnerability.

Security researchers at VulnCheck have observed clear signs of exploitation in the wild. Public-facing ProjectSend servers have been found with altered landing page titles, consistent with the behavior of both Nuclei and Metasploit exploit tools.

Technical Analysis

These tools modify the victim’s configuration file to change the site name, resulting in long, random-like strings appearing in HTTP titles.

More alarmingly, attackers are not limiting themselves to mere vulnerability testing. VulnCheck has noted widespread enabling of user registration settings, a non-default configuration that allows attackers to gain post-authentication privileges.

This suggests that malicious actors are likely moving beyond testing and potentially installing webshells or embedding malicious JavaScript. The vulnerability’s impact is exacerbated by poor patch adoption rates.

VulnCheck’s analysis of internet-facing ProjectSend instances revealed that only 1% are running the patched version (r1750). A staggering 55% are still using the vulnerable r1605 version released in October 2022, while 44% are on an unnamed release from April 2023.

Patch Adoption Graph (Source – VulnCheck)

Given the timeline of events, available exploits, and low patch adoption, security experts believe that exploitation is likely widespread and could increase significantly in the near future.

Vulnerability Timeline (Source – VulnCheck)

The vulnerability allows attackers to send crafted HTTP requests to options.php, enabling unauthorized modification of the application’s configuration.

Organizations using ProjectSend are strongly advised to immediately upgrade to version r1720 or later to mitigate this critical security risk.

Additionally, security teams should assess their exposure, implement necessary remediations, and conduct thorough incident response activities to detect any potential compromises.

This incident underscores the importance of prompt patching and the need for better coordination in vulnerability disclosure and CVE assignment processes.

As the threat landscape continues to evolve, staying vigilant and maintaining up-to-date security measures remains crucial for organizations of all sizes.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago