
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in LIVEBOX Collaboration vDesk through v018 related to unrestricted file upload vulnerabilities. The vulnerability allows an authenticated remote user to upload potentially dangerous files without restrictions under the vShare web site section (NVD).
The vulnerability is classified as an Unrestricted Upload of File with a Dangerous Type (CWE-434). It has received a CVSS v3.1 Base Score of 8.8 HIGH (Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The vulnerability affects LIVEBOX Collaboration vDesk versions up through v018 (NVD).
The vulnerability allows authenticated users to upload potentially dangerous files without any restrictions. This could lead to arbitrary code execution, system compromise, and potential data breaches. The high CVSS score indicates severe potential impacts on the confidentiality, integrity, and availability of the system (NVD).
The vulnerability requires authentication but has low attack complexity. An authenticated remote user can exploit this vulnerability by uploading dangerous files through the vShare web site section. The attack can be initiated remotely with low complexity (NVD).
Users should upgrade to a version newer than v018 if available. In the absence of a patch, it is recommended to implement strict file upload restrictions and validate file types before allowing uploads. Access to the vShare section should be strictly controlled (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."