CVE-2026-2334
9.4
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Summary
An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to Remote Code Execution (RCE) within the context of the web application. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| vsDesk | vsDesk | 14.0101 | affected |
| vsDesk | vsDesk | 14.0402 | unaffected |
Weaknesses
- CWE-434: CWE-434 Unrestricted upload of file with dangerous type
References
- https://github.com/klsecservices/Advisories/blob/master/KLSA-00415-Missing-Server-Side-File-Extension-Validation-in-vsDesk.md
- https://vsdesk.ru/news/vyshla-novaya-versiya-140422
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.