Lucene search

K
cvelistMitreCVELIST:CVE-2015-2993
HistoryJun 08, 2015 - 2:00 p.m.

CVE-2015-2993

2015-06-0814:00:00
mitre
www.cve.org
6

AI Score

6.6

Confidence

Low

EPSS

0.817

Percentile

98.4%

SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to /createnewaccount or (2) write to arbitrary files via the fileName parameter to /userentry.

AI Score

6.6

Confidence

Low

EPSS

0.817

Percentile

98.4%