CyberRota Analysis
AI-GeneratedThe vulnerability arises from the application's weak and predictable method of generating uploaded file names based on request timestamps, allowing remote attackers to guess or brute-force these filenames. This could lead to unauthorized access to sensitive files, potentially facilitating further attacks. Organizations using affected versions should prioritize applying the vendor's patch, particularly those running versions prior to 14.0101.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.