Impact
An authenticated attacker with administrative privileges can bypass client‑side file validation in the Import via CSV component of vsDesk v14.0101 because the application performs no server‑side file extension check. This flaw allows uploading an arbitrary file that is then executed as code in the web application context, giving the attacker full remote code execution capabilities and compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects the vsDesk application, specifically version 14.0101. The vendor has released a patch in versions 14.0402 and later that implements proper server‑side validation of uploaded file extensions.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. While the EPSS score is unavailable, the absence of a known exploitation status in CISA's KEV catalog does not reduce the importance of applying the patch. The attack requires administrative access, meaning the threat surface is limited to compromised or poorly protected admin credentials, but once active the attacker can run arbitrary code on the affected system.
OpenCVE Enrichment