6.8
CVSSv2

CVE-2021-43972

Published: 11/01/2022 Updated: 20/01/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:N/I:C/A:N

Vulnerability Summary

An unrestricted file copy vulnerability in /UserSelfServiceSettings.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated malicious user to copy arbitrary files on the server filesystem to the web root (with an arbitrary filename) via the tempFile and fileName parameters in the HTTP POST body.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sysaid sysaid 20.4.74