Remote Code Execution Vulnerability Affects UvDesk Community
CVE-2024-0916
10CRITICAL
Summary
A security flaw present in UvDesk Community allows for unauthenticated file uploads, which could lead to remote code execution. This vulnerability affects versions from 1.0.0 to 1.1.3, presenting a risk for environments where proper input validation and access controls are not in place. Attackers can exploit this weakness to upload malicious scripts, potentially compromising the integrity and security of the application. Best practices for remediation include upgrading to patched versions and implementing thorough security audits to mitigate any associated risks.
Affected Version(s)
UvDesk Community Linux 1.0.0 <= 1.1.3
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published