PT-2024-26280 · Unknown · Help Desk - Customer Support Management System

Published

2024-06-19

·

Updated

2024-08-01

·

CVE-2024-34990

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Help Desk - Customer Support Management System versions up to 2.4.0
Description The issue allows a customer to upload .php files. Methods HelpdeskHelpdeskModuleFrontController::submitTicket() and HelpdeskHelpdeskModuleFrontController::replyTicket() enable the upload of .php files on a predictable path for connected customers.
Recommendations For versions up to 2.4.0, consider disabling the HelpdeskHelpdeskModuleFrontController::submitTicket() and HelpdeskHelpdeskModuleFrontController::replyTicket() methods until a patch is available to prevent the upload of malicious .php files. Restrict access to file upload functionality for connected customers to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-34990

Affected Products

Help Desk - Customer Support Management System