CVE-2017-11512
manageengine servicedesk Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2017-11512 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 12, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ManageEngine ServiceDeskBrowse Zoho / ManageEngine ServiceDesk | CVE List | 9.3.9328 | affected |
servicedeskBrowse manageengine / servicedesk | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHManageEngine ServiceDesk 9.3.9328 - Arbitrary File RetrievalCVSS 7.5
ManageEngine ServiceDesk 9.3.9328 is vulnerable to an arbitrary file retrieval due to improper restrictions of the pathname used in the name parameter for the download-snapshot path. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.
Impact
An attacker can access sensitive files on the server, potentially leading to unauthorized access or data leakage.
Remediation
Upgrade to a patched version of ManageEngine ServiceDesk 9.3.9328 or apply the necessary security patches.
Source: ProjectDiscovery