Unauthenticated file upload allows remote code execution.
This issue affects UvDesk Community: from 1.0.0 through 1.1.3.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-16698 Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3.
Fixes

Solution

Apply the patch in this pull request: https://github.com/uvdesk/core-framework/pull/706


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Pentraze

Published:

Updated: 2024-08-06T18:40:07.287Z

Reserved: 2024-01-26T03:47:59.144Z

Link: CVE-2024-0916

cve-icon Vulnrichment

Updated: 2024-08-01T18:18:19.041Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-25T23:15:46.863

Modified: 2024-11-21T08:47:43.277

Link: CVE-2024-0916

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses