PT-2026-78896 · Vsdesk · Vsdesk
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
vsDesk versions prior to 14.0101
Description
The application uses a weak and predictable method based on the request timestamp to generate names for uploaded files. This flaw allows a remote attacker to guess or brute-force the generated filename within a short time window, enabling unauthorized access to uploaded files to facilitate further attacks.
Recommendations
Update to version 14.0101 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vsdesk