Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qpwx-f5jx-qhf4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious user to execute JSP code by uploading a zip that extracts files in relative paths.

Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious user to execute JSP code by uploading a zip that extracts files in relative paths.

EPSS

Процентиль: 61%
0.00418
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious user to execute JSP code by uploading a zip that extracts files in relative paths.

EPSS

Процентиль: 61%
0.00418
Низкий

Дефекты

CWE-434