Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qqv4-hj7r-xr74

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files from a specific directory via unspecified vectors.

FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files from a specific directory via unspecified vectors.

EPSS

Процентиль: 54%
0.00315
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 14 лет назад

FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files from a specific directory via unspecified vectors.

EPSS

Процентиль: 54%
0.00315
Низкий

Дефекты

CWE-287