PT-2024-32010 · Ladybird Web Solution · Faveo Helpdesk

Asad Iqbal

·

Published

2024-10-22

·

Updated

2024-10-23

·

CVE-2024-46482

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Ladybird Web Solution Faveo-Helpdesk version 2.0.3
Description The issue is related to an arbitrary file upload vulnerability in the Ticket Generation function. This allows attackers to execute arbitrary code by uploading crafted files, such as .html or .svg files.
Recommendations For Ladybird Web Solution Faveo-Helpdesk version 2.0.3, consider disabling the Ticket Generation function until a patch is available to prevent the upload of malicious files. Restrict access to this function to minimize the risk of exploitation. Avoid using the Ticket Generation feature with untrusted input until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-46482

Affected Products

Faveo Helpdesk