该应用在生成上传文件名时使用了基于请求时间戳的弱且可预测的方法。这使得远程攻击者能够在短时间内准确猜测或暴力破解生成的文件名。攻击者可以成功定位并访问已上传的文件,从而为后续攻击提供便利。 请应用来自厂商 https://vsdesk.ru/ 的补丁。14.0101 及以上版本已包含此补丁。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-2334 | 9.4 CRITICAL | ) Missing Server-Side File Extension Validation in vsDesk |
| CVE-2025-14601 | 8.6 HIGH | vsDesk Task Scheduler OS Command Injection |
No comments yet