Show filters
32 Total Results
Displaying 1-10 of 32
Sort by:
Attacker Value
Very High
CVE-2023-47246
Disclosure Date: November 10, 2023 (last updated August 15, 2024)
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
4
Attacker Value
Unknown
CVE-2024-36394
Disclosure Date: June 06, 2024 (last updated June 12, 2024)
SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
0
Attacker Value
Unknown
CVE-2024-36393
Disclosure Date: June 06, 2024 (last updated June 12, 2024)
SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
0
Attacker Value
Unknown
CVE-2024-27775
Disclosure Date: March 28, 2024 (last updated April 02, 2024)
SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's NTLMv2 hash
0
Attacker Value
Unknown
CVE-2023-47247
Disclosure Date: December 25, 2023 (last updated January 04, 2024)
In SysAid On-Premise before 23.3.34, there is an edge case in which an end user is able to delete a Knowledge Base article, aka bug 15102.
0
Attacker Value
Unknown
CVE-2023-33706
Disclosure Date: November 24, 2023 (last updated December 01, 2023)
SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modified srID parameter to ShowMessage.jsp.
0
Attacker Value
Unknown
CVE-2023-32226
Disclosure Date: July 30, 2023 (last updated October 08, 2023)
Sysaid - CWE-552: Files or Directories Accessible to External Parties -
Authenticated users may exfiltrate files from the server via an unspecified method.
0
Attacker Value
Unknown
CVE-2023-32225
Disclosure Date: July 30, 2023 (last updated October 08, 2023)
Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type -
A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.
0
Attacker Value
Unknown
CVE-2022-22796
Disclosure Date: May 09, 2022 (last updated February 23, 2025)
Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, then click on the login button, and it will redirect you to /home.jsp without any authentication.
0
Attacker Value
Unknown
CVE-2022-22798
Disclosure Date: May 09, 2022 (last updated February 23, 2025)
Sysaid – Pro Plus Edition, SysAid Help Desk Broken Access Control v20.4.74 b10, v22.1.20 b62, v22.1.30 b49 - An attacker needs to log in as a guest after that the system redirects him to the service portal or EndUserPortal.JSP, then he needs to change the path in the URL to /ConcurrentLogin%2ejsp after that he will receive an error message with a login button, by clicking on it, he will connect to the system dashboard. The attacker can receive sensitive data like server details, usernames, workstations, etc. He can also perform actions such as uploading files, deleting calls from the system.
0