Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m625-c2m5-3rmr

Опубликовано: 12 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

An unrestricted file copy vulnerability in /UserSelfServiceSettings.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to copy arbitrary files on the server filesystem to the web root (with an arbitrary filename) via the tempFile and fileName parameters in the HTTP POST body.

An unrestricted file copy vulnerability in /UserSelfServiceSettings.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to copy arbitrary files on the server filesystem to the web root (with an arbitrary filename) via the tempFile and fileName parameters in the HTTP POST body.

EPSS

Процентиль: 45%
0.00227
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
около 4 лет назад

An unrestricted file copy vulnerability in /UserSelfServiceSettings.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to copy arbitrary files on the server filesystem to the web root (with an arbitrary filename) via the tempFile and fileName parameters in the HTTP POST body.

EPSS

Процентиль: 45%
0.00227
Низкий