Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Bytedesk SVG File UploadRestController.java uploadFile unrestricted upload
Vulnerability Description
A security flaw has been discovered in Bytedesk up to 1.3.9. This affects the function uploadFile of the file source-code/src/main/java/com/bytedesk/core/upload/UploadRestController.java of the component SVG File Handler. Performing a manipulation results in unrestricted upload. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.4.5.1 is able to mitigate this issue. The patch is named 975e39e4dd527596987559f56c5f9f973f64eff7. Upgrading the affected component is recommended.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
Bytedesk 代码问题漏洞
Vulnerability Description
Bytedesk是bytedesk.com个人开发者的一个全渠道智能客服平台。 Bytedesk 1.3.9及之前版本存在代码问题漏洞,该漏洞源于对文件UploadRestController.java中uploadFile函数的操作,可能导致无限制上传。
CVSS Information
N/A
Vulnerability Type
N/A