#ProjectSend
Avec les changements de conditions d'utilisation de WeTransfer, vous êtes sans doute à la recherche d'alternatives auto-hébergeables et open-sources. Voici donc ProjectSend qui vous permettra de partager vos fichiers avec un contrôle total ⬇️

github.com/projectsend/...
GitHub - projectsend/projectsend: ProjectSend is a free, open source software that lets you share files with your clients, focused on ease of use and privacy. It supports clients groups, system users ...
ProjectSend is a free, open source software that lets you share files with your clients, focused on ease of use and privacy. It supports clients groups, system users roles, statistics, multiple lan...
github.com
July 16, 2025 at 6:06 AM
ProjectSend Development Dubai | Secure File Portals | CONSAI

ProjectSend development in Dubai for secure file portals, client access, project collaboration, workflows and GCC data control.

#CONSAI #AI #CRM #Automation #DubaiBusiness
June 21, 2026 at 5:23 AM
ProjectSend Development Dubai | Secure File Portals | CONSAI

ProjectSend development in Dubai for secure file portals, client access, project collaboration, workflows and GCC data control.

#CONSAI #AI #CRM #Automation #DubaiBusiness
June 8, 2026 at 11:59 AM
🚨 CVE-2024-11680: Critical ProjectSend Vulnerability:

CVSS 9.8 flaw in ProjectSend -that allows attackers to execute arbitrary code- actively exploited, with #PoC now public.

Link: securityonline.info/cve-2024-116...

#Cybersecurity #CVE #Vulnerability #Exploit #Infosec
CVE-2024-11680 (CVSS 9.8): Critical ProjectSend Vulnerability Actively Exploited, PoC Published
Critical vulnerability in ProjectSend (CVE-2024-11680) actively exploited. Learn how to protect your instance from unauthorized access and potential abuse.
securityonline.info
November 28, 2024 at 6:29 AM
ProjectSend Vulnerability Exploited In The Wild
ProjectSend Vulnerability Exploited In The Wild
packetstormsecurity.com
November 27, 2024 at 3:50 PM
🚨Proof of Concept (PoC) Exploit for CVE-2024-11680, Critical Vulnerability in ProjectSend

darkwebinformer.com/proof-of-con...
Proof of Concept (PoC) Exploit for CVE-2024-11680, Critical Vulnerability in ProjectSend
Proof of Concept (PoC) Exploit for CVE-2024-11680, Critical Vulnerability in ProjectSend
darkwebinformer.com
December 4, 2024 at 7:18 PM
CISA Warns of Active Exploitation of Flaws in Zyxel, ProjectSend, and CyberPanel #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
December 5, 2024 at 7:27 AM
ProjectSend critical flaw actively exploited in the wild, experts warn
ProjectSend critical flaw actively exploited in the wild, experts warn
Researchers warn that a critical security flaw in ProjectSend open-source file-sharing application may be under active exploitation.
securityaffairs.com
November 28, 2024 at 8:15 AM
Are the people you're sending files to too stupid to operate BitTorrent? Good news! Cool Nerds have invented ProjectSend
July 15, 2025 at 2:35 PM
CISA Warns of Active Exploitation of Flaws in Zyxel, ProjectSend, and CyberPanel
CISA Warns of Active Exploitation of Flaws in Zyxel, ProjectSend, and CyberPanel
thehackernews.com
December 5, 2024 at 6:18 AM
ProjectSend Vulnerability Exploited In The Wild - https://mwyr.es/y3ym1qYQ #securityweek #infosec
ProjectSend Vulnerability Exploited in the Wild
VulnCheck warns of widespread exploitation of a year-and-a-half-old ProjectSend vulnerability for which multiple public exploits exist.
www.securityweek.com
November 27, 2024 at 12:10 PM
Critical Flaw in ProjectSend Under Active Exploitation Against Public-Facing Servers
Critical Flaw in ProjectSend Under Active Exploitation Against Public-Facing Servers
Critical ProjectSend flaw (CVE-2024-11680) actively exploited. Update to version r1750 to secure your server.
thehackernews.com
November 28, 2024 at 2:12 AM
CISA Warns Of CyberPanel, North Grid, ProjectSend & Zyxel Firewalls Flaws Exploited In Wild
CISA Warns Of CyberPanel, North Grid, ProjectSend & Zyxel Firewalls Flaws Exploited In Wild
The Cybersecurity and Infrastructure Security Agency Warns of CyberPanel, North Grid, ProjectSend & Zyxel firewalls flaws exploited in wild.
cybersecuritynews.com
December 5, 2024 at 9:06 AM
Notícia da BleepingComputer

"Hackers exploram falha do ProjectSend para inserir backdoor em servidores expostos" #bolhasec
Hackers exploit ProjectSend flaw to backdoor exposed servers
Threat actors are using public exploits for a critical authentication bypass flaw in ProjectSend to upload webshells and gain remote access to servers. [...]
www.bleepingcomputer.com
November 28, 2024 at 2:04 PM
Auch wenn ein Sicherheitspatch für ProjectSend schon länger als ein Jahr verfügbar ist, sind offensichtlich noch unzählige Instanzen verwundbar. #Security
Jetzt patchen! Attacken auf Filesharingplattform ProjectSend beobachtet
Auch wenn ein Sicherheitspatch für ProjectSend schon länger als ein Jahr verfügbar ist, sind offensichtlich noch unzählige Instanzen verwundbar.
www.heise.de
November 29, 2024 at 9:21 AM
Threat actors are using public exploits for a critical authentication bypass flaw in ProjectSend to upload webshells and gain remote access to servers.
www.bleepingcomputer.com/news/securit...
Hackers exploit ProjectSend flaw to backdoor exposed servers
Threat actors are using public exploits for a critical authentication bypass flaw in ProjectSend to upload webshells and gain remote access to servers.
www.bleepingcomputer.com
November 27, 2024 at 9:05 PM
Hackers exploit a critical ProjectSend flaw (CVE-2024-11680) to backdoor thousands of exposed servers. A May 2023 patch exists but adoption is low, leaving systems vulnerable to webshell deployment and remote access. Upgrade to r1750 immediately.
November 27, 2024 at 10:00 PM
ProjectSend devs shipped a turd sandwich. Now miscreants are finger-blasting gaping security holes, likely dropping webshells faster than Hunter S. Thompson dropped acid. Patch now or face digital ruin. Your files? So not yours anymore.

vulncheck.com/blog/p...
ProjectSend CVE-2024-11680 Exploited in the Wild - Blog - VulnCheck
VulnCheck discovers evidence that ProjectSend has been exploited in the wild and assigns CVE-2024-11680
vulncheck.com
December 2, 2024 at 7:56 PM
🚨 Attackers are exploiting #ProjectSend servers vulnerable to #CVE-2024-11680 (CVSS 9.8). Only 1% of instances are patched (r1720), leaving 55% open to webshells & rogue accounts. Update now to block exploits spreading via #Metasploit & #Nuclei. Patch or risk compromise! #CyberSecurity
December 3, 2024 at 9:46 AM
U.S. CISA adds ProjectSend, North Grid Proself, and Zyxel firewalls bugs to its Known Exploited Vulnerabilities catalog securityaffairs.com/171638/secur...
December 4, 2024 at 8:12 AM
Hackers Exploiting ProjectSend Authentication Vulnerability In The Wild
Hackers Exploiting ProjectSend Authentication Vulnerability In The Wild
Hackers are actively exploiting a critical authentication vulnerability in ProjectSend, a popular open-source file-sharing web application. The vulnerability, now identified as CVE-2024-11680, allows remote, unauthenticated attackers to bypass authentication and modify the application’s configuration, potentially leading to unauthorized account creation, webshell uploads, and malicious JavaScript injection. Despite the patch being available since May 16, 2023, the CVE was only assigned on November 26, 2024, leaving many systems exposed for over a year. The delay in CVE assignment is particularly notable given that Rapid7, a CVE Numbering Authority, had already published a Metasploit module for this vulnerability. Security researchers at VulnCheck have observed clear signs of exploitation in the wild. Public-facing ProjectSend servers have been found with altered landing page titles, consistent with the behavior of both Nuclei and Metasploit exploit tools. Technical Analysis These tools modify the victim’s configuration file to change the site name, resulting in long, random-like strings appearing in HTTP titles. More alarmingly, attackers are not limiting themselves to mere vulnerability testing. VulnCheck has noted widespread enabling of user registration settings, a non-default configuration that allows attackers to gain post-authentication privileges. This suggests that malicious actors are likely moving beyond testing and potentially installing webshells or embedding malicious JavaScript. The vulnerability’s impact is exacerbated by poor patch adoption rates. VulnCheck’s analysis of internet-facing ProjectSend instances revealed that only 1% are running the patched version (r1750). A staggering 55% are still using the vulnerable r1605 version released in October 2022, while 44% are on an unnamed release from April 2023. Patch Adoption Graph (Source – VulnCheck) Given the timeline of events, available exploits, and low patch adoption, security experts believe that exploitation is likely widespread and could increase significantly in the near future. Vulnerability Timeline (Source – VulnCheck) The vulnerability allows attackers to send crafted HTTP requests to options.php, enabling unauthorized modification of the application’s configuration. Organizations using ProjectSend are strongly advised to immediately upgrade to version r1720 or later to mitigate this critical security risk . Additionally, security teams should assess their exposure, implement necessary remediations, and conduct thorough incident response activities to detect any potential compromises. This incident underscores the importance of prompt patching and the need for better coordination in vulnerability disclosure and CVE assignment processes. As the threat landscape continues to evolve, staying vigilant and maintaining up-to-date security measures remains crucial for organizations of all sizes. The post Hackers Exploiting ProjectSend Authentication Vulnerability In The Wild appeared first on Cyber Security News .
cybersecuritynews.com
November 27, 2024 at 12:15 PM
Love this idea, but despise kim dotcom, he hung out with lots of transphobes in twit spaces, was a fed co-operator in my case, snitched so hard he got himself raided. I was going to be setting up a projectsend installation or similar software for sharing trans related files/knowledge like this.
November 7, 2024 at 7:53 AM