PT-2026-78896 · Vsdesk · Vsdesk

·

CVE-2025-14602

·

Published

2026-08-20

·

Updated

2026-08-20

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions vsDesk versions prior to 14.0101
Description The application uses a weak and predictable method based on the request timestamp to generate names for uploaded files. This flaw allows a remote attacker to guess or brute-force the generated filename within a short time window, enabling unauthorized access to uploaded files to facilitate further attacks.
Recommendations Update to version 14.0101 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-14602

Affected Products

Vsdesk