CVE-2022-39983: arbitrary file upload in the Instant Developer RD3 framework
A library in Instant Developer's RD3 framework allows arbitrary file upload and remote code execution on every web app built with versions prior to 22.5 r23.
- CVE
- CVE-2022-39983
- Product
- Instant Developer RD3 Framework < 22.5 r23
- CVSS
- 9.8
- Severity
- critical
- Status
- patched
TL;DR
The Instant Developer RD3 framework, in
versions prior to 22.5 r23, contains in the full.js library an upload
endpoint that does not restrict the type of file that can be uploaded. An attacker
with a valid authenticated session can upload an .aspx web shell and execute
arbitrary commands on the server. The flaw affects all applications built with
the vulnerable versions of the framework.
Research I carried out in my work at Tinexta Cyber, published under responsible disclosure.
Context
Instant Developer is a family of low-code platforms for building multi-channel applications. Because it is a framework, a vulnerability inside it propagates to every application that inherits its runtime: not a single product, but the entire fleet of client web apps that use it.
Details
| Asset | Vulnerability | CVSS v3.1 | Severity |
|---|---|---|---|
| Instant Developer RD3 Framework < 22.5 r23 | Arbitrary File Upload | 9.8 | Critical |
- CWE-434: Unrestricted Upload of File with Dangerous Type
- CVSS v3.1 vector:
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - OWASP Top 10 2021: A04 — Insecure Design
The vulnerability lives in the framework’s full.js library. Analysing the
client-side code made it possible to identify the entry point responsible for the
upload and to reconstruct the request needed to send an arbitrary file. This lets
an attacker upload malicious files to execute arbitrary code (for example a reverse
shell) and, from there, hunt for credentials, move laterally across the
infrastructure or cause disruption.
The vulnerable endpoint has the form:
https://<TARGET>/<app>/<file>.aspx/?WCI=IWFiles&WCE=&SESSIONID=<SESSION_ID>
Proof of Concept
Analysing full.js reveals the code handling the upload.

Once the request was reconstructed, it was possible to upload an .aspx reverse
shell with a simple curl call:
curl -kis -F "Filedata=@<MALICIOUS_FILE>.aspx" \
-H "Cookie: ASP.NET_SessionId=<SESSION_ID>" \
-A Chrome \
"https://<TARGET>/<app>/<file>.aspx/?WCI=IWFiles&WCE=&SESSIONID=<SESSION_ID>"


Fix and mitigations
Rebuild the application with the latest version of the framework (22.5 r23 or later).
Vendor considerations
During disclosure the vendor provided some clarifications on the exploitation conditions and on the countermeasures introduced:
- Exploiting the flaw requires knowing the
SessionIDof an authenticated session: access to a browser with an active login session is needed. - If the developer has not removed authentication from their application, since version 20.5 the system does not allow uploads in unauthenticated sessions. It is up to the programmer to validate credentials and authorise access.
- Since version 22.0, the application’s
TEMPfolder contains a file that prevents execution of arbitrary files: it must not be removed and must be installed correctly in production. - On upload from an authenticated session, it is up to the programmer to decide
whether to accept the file by implementing the
OnFileUploadevent; a rejected file is immediately removed from disk. - Pro Gamma provides a general-purpose development environment: it is the programmer’s responsibility to develop the application and configure the web server when it is exposed on the internet.
Timeline
| Date | Event |
|---|---|
| 2022-07-25 | Vulnerability discovered |
| 2022-08-24 | First contact with the vendor (no reply) |
| 2022-08-29 | CVE-ID requested from MITRE |
| 2022-09-07 | Second contact with the vendor (reply received) |
| 2022-09-15 | Report shared with the vendor |
| 2023-01-23 | Version 22.5 r23 released |
| 2023-02-15 | CVE-2022-39983 assigned |
| 2023-02-20 | Security advisory published |