Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f32q-24fc-cjxj

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to /createnewaccount or (2) write to arbitrary files via the fileName parameter to /userentry.

SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to /createnewaccount or (2) write to arbitrary files via the fileName parameter to /userentry.

EPSS

Процентиль: 99%
0.77003
Высокий

Связанные уязвимости

nvd
больше 10 лет назад

SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to /createnewaccount or (2) write to arbitrary files via the fileName parameter to /userentry.

EPSS

Процентиль: 99%
0.77003
Высокий