Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2021-43973

Disclosure Date: January 11, 2022 (last updated February 23, 2025)
An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to upload an arbitrary file via the file parameter in the HTTP POST body. A successful request returns the absolute, server-side filesystem path of the uploaded file.
Attacker Value
Unknown

CVE-2021-43972

Disclosure Date: January 11, 2022 (last updated February 23, 2025)
An unrestricted file copy vulnerability in /UserSelfServiceSettings.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to copy arbitrary files on the server filesystem to the web root (with an arbitrary filename) via the tempFile and fileName parameters in the HTTP POST body.
Attacker Value
Unknown

CVE-2021-43971

Disclosure Date: January 11, 2022 (last updated February 23, 2025)
A SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to execute arbitrary SQL commands via the filterText parameter.
Attacker Value
Unknown

CVE-2021-31862

Disclosure Date: October 29, 2021 (last updated February 23, 2025)
SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.