Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
) Missing Server-Side File Extension Validation in vsDesk
Vulnerability Description
An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to Remote Code Execution (RCE) within the context of the web application.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
vsDesk 任意文件上传漏洞
Vulnerability Description
vsDesk是vsDesk组织的一款服务器与网络管理设备。 vsDesk 14.0101版本存在任意文件上传漏洞,该漏洞源于“Import via CSV”组件缺乏服务端验证,允许绕过客户端文件验证上传任意文件,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A