Unrestricted File Upload Vulnerability in SysAid ITIL Software
CVE-2021-43973
8.8HIGH
Summary
An unrestricted file upload vulnerability in SysAid ITIL 20.4.74 b10 allows authenticated remote attackers to upload arbitrary files via the 'file' parameter in the HTTP POST request. This flaw can lead to significant security risks, as attackers can leverage the vulnerability to upload malicious files, potentially gaining access to sensitive information. Upon successful exploitation, the server may return the absolute filesystem path of the uploaded file, further aiding attackers in crafting further malicious actions.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved