PT-2024-27879 · Vesystem · Vesystem Cloud Desktop

H0E4A0R1T

·

Published

2024-04-15

·

Updated

2024-06-04

·

CVE-2024-3804

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Vesystem Cloud Desktop up to 20240408
Description A critical issue has been found in the processing of the file /Public/webuploader/0.1.5/server/fileupload2.php. The manipulation of the file argument leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations For Vesystem Cloud Desktop up to 20240408, as a temporary workaround, consider restricting access to the /Public/webuploader/0.1.5/server/fileupload2.php file until a patch is available. Avoid using the file argument in the affected file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-3804

Affected Products

Vesystem Cloud Desktop