Showing 2 vulnerabilities on this page for servicedesk

Signals CISA KEV Ransomware Nuclei
ManageEngine vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

manageengine servicedesk Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.

CWE-22Nov 8, 20171 related artifact
CVSS7.5v3.0EPSS79.6%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

manageengine servicedesk Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath parameter for the download-file URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.

CWE-200CWE-22Nov 8, 2017
CVSS7.5v3.0EPSS3.54%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX