The application generates uploaded file names using a...
Moderate severity
Unreviewed
Published
Aug 20, 2026
to the GitHub Advisory Database
•
Updated Aug 20, 2026
Description
Published by the National Vulnerability Database
Aug 20, 2026
Published to the GitHub Advisory Database
Aug 20, 2026
Last updated
Aug 20, 2026
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
References