PT-2021-20864 · Unknown · Web Help Desk
Published
2021-12-23
·
Updated
2022-01-07
·
CVE-2021-35243
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Web Help Desk versions 12.7.7 and earlier
Description:
The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server, allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data that is saved on the server with a user-supplied URL. While the DELETE method requests that the origin server removes the association between the target resource and its current functionality. Improper use of these methods may lead to a loss of integrity.
Recommendations:
For versions 12.7.7 and earlier, consider disabling the HTTP PUT and DELETE methods to prevent users from executing dangerous HTTP requests until a patch is available. Restrict access to the Web Help Desk web server to minimize the risk of exploitation. Avoid using user-supplied URLs for uploading data to the server.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Web Help Desk