8.8

CVE-2026-3748

Exploit

Bytedesk SVG File UploadRestController.java uploadFile unrestricted upload

A security flaw has been discovered in Bytedesk up to 1.3.9. This affects the function uploadFile of the file source-code/src/main/java/com/bytedesk/core/upload/UploadRestController.java of the component SVG File Handler. Performing a manipulation results in unrestricted upload. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.4.5.1 is able to mitigate this issue. The patch is named 975e39e4dd527596987559f56c5f9f973f64eff7. Upgrading the affected component is recommended.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BytedeskBytedesk Version < 1.4.5.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.377
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cna@vuldb.com 2.1 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cna@vuldb.com 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
cna@vuldb.com 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://vuldb.com/?id.349726
Third Party Advisory
VDB Entry
https://vuldb.com/?ctiid.349726
Permissions Required
https://vuldb.com/?submit.768028
Third Party Advisory
VDB Entry
https://github.com/Bytedesk/bytedesk/issues/18
Vendor Advisory
Exploit
Issue Tracking
https://github.com/Bytedesk/bytedesk/issues/18#issuecomment-3976672973
Vendor Advisory
Exploit
Issue Tracking
https://github.com/Bytedesk/bytedesk/issues/18#issue-3993448721
Vendor Advisory
Exploit
Issue Tracking
https://github.com/Bytedesk/bytedesk/commit/975e39e4dd527596987559f56c5f9f973f64eff7
Patch
https://github.com/Bytedesk/bytedesk/releases/tag/v1.4.5.1
Release Notes
https://github.com/Bytedesk/bytedesk/
Product