目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-11680 PoC — ProjectSend 安全漏洞

来源
关联漏洞
标题: ProjectSend 安全漏洞 (CVE-2024-11680)
Description:ProjectSend(cFTP)是ProjectSend开源的一套基于PHP和MySQL的自托管应用程序。 ProjectSend r1720之前版本存在安全漏洞,该漏洞源于受到身份验证漏洞的影响,远程未经身份验证的攻击者可以通过发送精心设计的HTTP请求实现对应用程序配置的未经授权修改。
Description
This repository contains a Proof of Concept (PoC) exploit for CVE-2024-11680, a critical vulnerability in ProjectSend r1605 and older versions. The exploit targets a Cross-Site Request Forgery (CSRF) flaw in combination with Privilege Misconfiguration issues.
介绍
# CVE-2024-11680 PoC Exploit
This repository contains a Proof of Concept (PoC) exploit for CVE-2024-11680, a critical vulnerability in ProjectSend r1605 and older versions. The exploit targets a Cross-Site Request Forgery (CSRF) flaw in combination with Privilege Misconfiguration issues.

![alt text](https://i.imgur.com/C2F7CFy.png)

---

## Features
- Exploits CSRF to modify the application title. This is the vulnerability confirmation.
- Enables insecure options (client registration, auto-approval, and file uploads).
- Registers a new user to demonstrate privilege misconfiguration issues.
- Automatically restores the original application title after testing.

---

## Usage

### Prerequisites
1. A valid target running r1605 or earlier of **ProjectSend**.
2. curl: This script uses curl to send HTTP requests.
You can check if curl is installed by running:

```bash command -v curl```

If it's not installed, you can install it using your package manager. For example, on Ubuntu:

```sudo apt-get install curl```


### Running the Exploit
1. Clone this repository or download the script.
2. Run the exploit using the following syntax:
   ```./exploit -u TARGET_URL```
4. Check the output for the generated username and password for the registered user.

---

## Disclaimer
This exploit is intended for ethical testing within authorized environments, such as responsible disclosure programs or Vulnerability Disclosure Programs (VDPs). The authors are not responsible for misuse or unauthorized actions taken using this script.

---

## Author
**D3N14LD15K**  
- d3n14ld15k[at]bugcrowdninja[dot]com
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →