Laserfiche Forms Portal File Upload Vulnerability.

September 17, 2021 | KB: 1014315
Forms 9, Forms 10, Forms 11

Summary

Laserfiche has identified a security vulnerability with self-hosted Laserfiche Forms. A summary of the vulnerability is below. Laserfiche has released a critical security update in order to address the issue. If you have not already applied this update, it should be applied immediately on Laserfiche Forms servers that are accessible from the public Internet or other open networks.

Is this vulnerability being used in an active exploit?

Yes. The vulnerability described here in this advisory is being exploited in a way where an unauthenticated third party can use Laserfiche Forms to temporarily host uploaded files for distribution. Valid customer form submission data is not impacted and is not accessible to the third party. The security updates address this vulnerability by reducing the time frame where the temporary file download link is active.

What is the target for this exploit?

The target for the exploit is Laserfiche Forms installations and process that have a public form that includes a file upload field.

Files uploaded by authenticated users are not affected as the download links will require authentication to access.

Exploitability

See the following exploitability assessment for this vulnerability at the time of original publication.

Publicly Disclosed Exploited Exploitability Assessment
Yes Yes Exploitation Detected

Mitigations

We recommend prioritizing installing updates on Laserfiche Forms servers that are externally facing, as the vulnerability can be exploited by unauthenticated users. The following Laserfiche Forms security updates modify the default behavior of public forms to no longer provide a download link.

Security Updates

Software Version Security Update
11 1014332: List of Changes for Laserfiche Forms 11 Update 1 Hotfix 1014332
10.4.5 1014333: List of Changes for Laserfiche Forms 10.4.5 Update 1
10.4.4 1014320: List of Changes for Laserfiche Forms 10.4.4 Update 1
10.4.3 1014321: List of Changes for Laserfiche Forms 10.4.3 Update 2
10.4.2 1014331: List of Changes for Laserfiche Forms 10.4.2 Update 1
10.4.1 1014328: List of Changes for Laserfiche Forms 10.4.1 Update 3
10.4.0 1014325: List of Changes for Laserfiche Forms 10.4.0 Update 1
10.3.1 1014326: List of Changes for Laserfiche Forms 10.3.1 Update 4
10.2.1 1014327: List of Changes for Laserfiche Forms 10.2.1 Update 6
9.2.1 1014336: List of Changes for Laserfiche Forms 9.2.1 Hotfix 1014336
9.1.1 1014334: List of Changes for Laserfiche Forms 9.1.1 Hotfix 1014334
9.0.1 1014335: List of Changes for Laserfiche Forms 9.0.1 Hotfix 1014335

Diagnostic Tool

Laserfiche Forms Public Portal File Cleanup Tool