An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.wyomind.com/magento2/helpdesk-magento-2.html | product |
https://www.exploit-db.com/exploits/50113 | third party advisory vdb entry exploit |