Show filters
38 Total Results
Displaying 1-10 of 38
Sort by:
Attacker Value
Very High
CVE-2023-47246
Disclosure Date: November 10, 2023 (last updated August 15, 2024)
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
4
Attacker Value
Unknown
CVE-2024-36394
Disclosure Date: June 06, 2024 (last updated June 12, 2024)
SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
0
Attacker Value
Unknown
CVE-2024-36393
Disclosure Date: June 06, 2024 (last updated June 12, 2024)
SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
0
Attacker Value
Unknown
CVE-2024-27775
Disclosure Date: March 28, 2024 (last updated April 02, 2024)
SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's NTLMv2 hash
0
Attacker Value
Unknown
CVE-2023-47247
Disclosure Date: December 25, 2023 (last updated January 04, 2024)
In SysAid On-Premise before 23.3.34, there is an edge case in which an end user is able to delete a Knowledge Base article, aka bug 15102.
0
Attacker Value
Unknown
CVE-2023-33706
Disclosure Date: November 24, 2023 (last updated December 01, 2023)
SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modified srID parameter to ShowMessage.jsp.
0
Attacker Value
Unknown
CVE-2023-32226
Disclosure Date: July 30, 2023 (last updated October 08, 2023)
Sysaid - CWE-552: Files or Directories Accessible to External Parties -
Authenticated users may exfiltrate files from the server via an unspecified method.
0
Attacker Value
Unknown
CVE-2023-32225
Disclosure Date: July 30, 2023 (last updated October 08, 2023)
Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type -
A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.
0
Attacker Value
Unknown
CVE-2022-40325
Disclosure Date: September 11, 2022 (last updated February 24, 2025)
SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262.
0
Attacker Value
Unknown
CVE-2022-40324
Disclosure Date: September 11, 2022 (last updated February 24, 2025)
SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258.
0