Skip to content

Commit e7b04ab

Browse files
author
jenkins-metasploit
committed
automatic module_metadata_base.json update
1 parent 136599a commit e7b04ab

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

db/modules_metadata_base.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -81376,6 +81376,7 @@
8137681376
],
8137781377
"description": "This module exploits an improper authorization vulnerability in ProjectSend versions r1295 through r1605.\n The vulnerability allows an unauthenticated attacker to obtain remote code execution by enabling user registration,\n disabling the whitelist of allowed file extensions, and uploading a malicious PHP file to the server.",
8137881378
"references": [
81379+
"CVE-2024-11680",
8137981380
"URL-https://github.com/projectsend/projectsend/commit/193367d937b1a59ed5b68dd4e60bd53317473744",
8138081381
"URL-https://www.synacktiv.com/sites/default/files/2024-07/synacktiv-projectsend-multiple-vulnerabilities.pdf",
8138181382
"CVE-2024-11680"
@@ -81401,7 +81402,7 @@
8140181402
"targets": [
8140281403
"PHP Command"
8140381404
],
81404-
"mod_time": "2024-12-07 14:23:30 +0000",
81405+
"mod_time": "2024-12-11 13:54:06 +0000",
8140581406
"path": "/modules/exploits/linux/http/projectsend_unauth_rce.rb",
8140681407
"is_install_path": true,
8140781408
"ref_name": "linux/http/projectsend_unauth_rce",

0 commit comments

Comments
 (0)