logo

CVE-2023-47246 - SysAid Server Path Traversal Vulnerability

Project:SysAid

Product:SysAid Server

Date Added:2023-11-13Due Date:2023-12-04

Vulnerability Name

SysAid Server Path Traversal Vulnerability

Description

SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution.

Known To Be Used in Ransomware Campaigns?

Known

Action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Additional Notes

https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification

https://nvd.nist.gov/vuln/detail/CVE-2023-47246