Sceawere
Vulnerability Detail
CVE-2026-62024UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CodeBard Help Desk Unrestricted Upload
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 5h ago
- Vendor
- CodeBard
- Product
- CodeBard Help Desk
- Attack Type
- CWE-434 Unrestricted Upload of File with Dangerous Type
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Arbitrary File Upload in CodeBard Help Desk <= 1.1.2 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-10-10T20:16:38.750Z",
"pubdate": "2026-10-10T20:16:38.750Z",
"executiveSummary": "The CodeBard Help Desk plugin, specifically in versions 1.1.2 and earlier, contains an arbitrary file upload vulnerability. This security flaw stems from insufficient validation of user-supplied files during the upload process.\nThe vulnerability allows an authenticated user with subscriber-level access to bypass intended restrictions and upload malicious files, such as PHP scripts, to the web server.\nThis represents a critical risk, as successful exploitation enables remote code execution (RCE). By interacting with the uploaded malicious payload, an attacker can achieve full system compromise, access sensitive configuration files, modify application data, or pivot further into the underlying network infrastructure.\nThe exploitation does not require administrative privileges, as the vulnerability is accessible to any registered subscriber. This significantly lowers the barrier for exploitation, making it a high-priority threat for organizations utilizing the affected plugin version.",
"technicalDetails": "The root cause of this vulnerability lies in the improper implementation of server-side file type and extension validation within the CodeBard Help Desk plugin's file handling mechanisms. The application fails to strictly enforce an allowlist of permitted file extensions or verify the MIME type of incoming uploads before storing them in a publicly accessible web directory.\nThe vulnerability is accessible through the plugin's file upload interface, which is exposed to users with subscriber-level permissions. An attacker can initiate a request to the vulnerable endpoint, supplying a crafted payload—typically a web shell—with a malicious extension or a spoofed header intended to bypass existing filters.\nThe attack flow begins when an authenticated attacker submits a multipart/form-data request containing an arbitrary file. Because the application logic does not sufficiently sanitize or validate the filename and content, the server saves the file to a location reachable by the web server's execution context. If the server is misconfigured to execute scripts within the upload directory, the attacker can then request the uploaded file directly via a web browser using standard HTTP protocols.\nOnce the malicious script is triggered, the attacker gains the ability to execute arbitrary code with the privileges of the web server process (e.g., www-data). This effectively bypasses the application's intended security controls. Post-exploitation capabilities include the ability to traverse the server filesystem, execute system-level commands, establish reverse shells for persistent access, and exfiltrate sensitive data such as database credentials stored in wp-config.php.\nThe affected component is the internal file upload routine of the CodeBard Help Desk plugin. All versions up to and including 1.1.2 are susceptible. The primary requirement for exploitation is a valid subscriber account, which is a low privilege threshold in many WordPress environments that permit open registration. Network exposure is high, as the vulnerability is reachable through the standard HTTP/HTTPS entry points of the WordPress installation."
}