OpsBuzz

Alert

ProjectSend Improper Authentication Vulnerability

ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the app

Security · HIGH
Source: CISA Known Exploited VulnerabilitiesMay 2, 2026, 4:51 PMSecurityhigh

Full content

ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

Vendor: ProjectSend

Product: ProjectSend

Due date: 2024-12-24

Known ransomware use: Unknown

Why it matters

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Related alerts

ProjectSend Improper Authentication Vulnerability | OpsBuzz