在 vsDesk 中存在操作系统命令注入漏洞,允许具有管理员权限的已认证攻击者通过输入过滤不足执行任意操作系统命令。攻击者可利用此缺陷破坏 Web 服务器运行、暴露敏感数据,或可能实现完全控制服务器。 请从供应商 https://vsdesk.ru/ 应用补丁。14.0101 及更高版本已包含补丁。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-2334 | 9.4 CRITICAL | ) Missing Server-Side File Extension Validation in vsDesk |
| CVE-2025-14602 | 5.3 MEDIUM | Weak File Name Generation in vsDesk |
No comments yet