CyberRota Analysis
AI-GeneratedAn authenticated attacker with administrative privileges in vsDesk v14.0101 can exploit a lack of server-side validation in the "Import via CSV" component to bypass client-side file validation, enabling the upload of arbitrary files. This vulnerability can lead to Remote Code Execution (RCE) within the web application, posing a critical risk to affected systems. Organizations using this version should prioritize applying the vendor's patch, as versions 14.0402 and later contain the fix.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to Remote Code Execution (RCE) within the context of the web application. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.