VYPR

vsDesk

by VsDesk

CVEs (5)

  • CVE-2026-2334CriAug 20, 2026
    risk 0.61cvss —epss 0.01

    An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to…

  • CVE-2025-14600CriAug 19, 2026
    risk 0.60cvss —epss 0.01

    An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access. By manipulating application configuration data, an attacker can force the system to authenticate against an arbitrary LDAP server and provision a new…

  • CVE-2025-14603HigAug 19, 2026
    risk 0.57cvss —epss 0.00

    The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive.  Apply patch from vendor https://vsdesk.ru/ .…

  • CVE-2025-14601HigAug 20, 2026
    risk 0.56cvss —epss 0.01

    An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to insufficient input filtering. An attacker can exploit this flaw to disrupt web server operations, expose…

  • CVE-2025-14602MedAug 20, 2026
    risk 0.34cvss —epss 0.00

    The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access…