Junglewise Threat Intelligence

CVE-2024-31453: PsiTransfer unrestricted file upload to distribution

CVE-2024-31453 · Severity: low · CVSS 3.1 · Published 2024-04-05

Technologies: Psi-4ward Psitransfer. Vendors: npm.

Executive brief

PsiTransfer is an open-source file distribution application that allows users to share files securely. A vulnerability in the file upload endpoint allows an attacker without authentication to inject arbitrary files into an existing file distribution, enabling delivery of malicious or phishing content to legitimate users who download from that distribution.

Technical details

The vulnerability exists in the POST /files endpoint due to insufficient access control on the file upload mechanism. An attacker can exploit this by first creating or identifying a file distribution, then using the Upload-Metadata header to reference the target distribution's session ID (sid), allowing them to upload new files without proper authorization. The attack requires user interaction (the victim must visit and download from the compromised distribution), but no authentication is required from the attacker. Once exploited, attackers can inject files with malicious or phishing payloads into legitimate distributions, compromising integrity. The vulnerability was patched in version 2.2.0.

Affected products

  • psi-4ward PsiTransfer before 2.2.0

Timeline

  • 2024-04-05: disclosed
  • 2024-04-05: patched: Fixed in version 2.2.0

References

Related threats