Описание
Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to execute arbitrary code.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- ExploitMailing ListThird Party Advisory
- Permissions Required
- Permissions Required
- ExploitThird Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- ExploitMailing ListThird Party Advisory
- Permissions Required
- Permissions Required
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:manageengine:servicedesk_plus:-:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:manageengine:assetexplorer:-:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:a:manageengine:supportcenter:-:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:a:manageengine:it360:-:*:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.53882
Средний
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to execute arbitrary code.
EPSS
Процентиль: 98%
0.53882
Средний
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-22