CVE-2015-2993

SysAid Help Desk <15.2 - RCE

Title source: llm

Description

SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to /createnewaccount or (2) write to arbitrary files via the fileName parameter to /userentry.

Exploits (2)

exploitdb WORKING POC
webappshardware
https://www.exploit-db.com/exploits/43885
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/sysaid_admin_acct.rb

Scores

EPSS 0.7700
EPSS Percentile 99.0%

Details

CWE
CWE-264
Status published
Products (1)
sysaid/sysaid < 15.1
Published Jun 08, 2015
Tracked Since Feb 18, 2026