PT-2017-13387 · Mirasvit · Mirasvit Helpdesk Mx
Published
2017-09-21
·
Updated
2017-10-04
·
CVE-2017-14320
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mirasvit Helpdesk MX versions prior to 1.5.3
Description
The issue is related to the failure to filter uploaded files, which might allow remote attackers to execute arbitrary code.
Recommendations
For versions prior to 1.5.3, update to version 1.5.3 or later to resolve the issue. As a temporary workaround, consider restricting file uploads until the update is applied.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mirasvit Helpdesk Mx