CVE-2024-0916: Unauthenticated Remote Code Execution in UvDesk Community
Published Apr 25, 2024
·Updated
Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3.
Affected Software
1 affected component
Uvdesk Community>=1.0.0<=1.1.3
Remediation
Information
Apply the patch in this pull request:
https://github.com/uvdesk/core-framework/pull/706
Event History
Apr 25, 2024
CVE Published
via MITRE·11:02 PM
Data Sourced
via MITRE·11:02 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-0916?
CVE-2024-0916 is rated as critical due to its potential for remote code execution.
2
How do I fix CVE-2024-0916?
To fix CVE-2024-0916, upgrade UvDesk Community to a version higher than 1.1.3.
3
Who is affected by CVE-2024-0916?
CVE-2024-0916 affects all versions of UvDesk Community from 1.0.0 to 1.1.3.
4
What type of vulnerability is CVE-2024-0916?
CVE-2024-0916 is an unauthenticated file upload vulnerability that allows for remote code execution.
5
What should I do if I can't update to a fixed version for CVE-2024-0916?
If unable to update for CVE-2024-0916, consider implementing application firewalls and restricting file uploads.