CVE-2015-2993
SysAid Help Desk <15.2 - RCE
Title source: llmDescription
SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to /createnewaccount or (2) write to arbitrary files via the fileName parameter to /userentry.
Exploits (2)
metasploit
WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/sysaid_admin_acct.rb
References (5)
Scores
EPSS
0.7700
EPSS Percentile
99.0%
Details
CWE
CWE-264
Status
published
Products (1)
sysaid/sysaid
< 15.1
Published
Jun 08, 2015
Tracked Since
Feb 18, 2026