Lucene search

K
cvelistMitreCVELIST:CVE-2021-43972
HistoryJan 11, 2022 - 7:19 p.m.

CVE-2021-43972

2022-01-1119:19:23
mitre
www.cve.org
4
sysaid itil 20.4.74
unrestricted file copy
remote authenticated attacker
server filesystem
http post<body
arbitrary filename

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

43.7%

An unrestricted file copy vulnerability in /UserSelfServiceSettings.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to copy arbitrary files on the server filesystem to the web root (with an arbitrary filename) via the tempFile and fileName parameters in the HTTP POST body.

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

43.7%

Related for CVELIST:CVE-2021-43972