CVE-2023-47246 - SysAid Server Path Traversal Vulnerability
Project:SysAid
Product:SysAid Server
Date Added:2023-11-13Due Date:2023-12-04
Vulnerability Name
SysAid Server Path Traversal Vulnerability
Description
SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution.
Known To Be Used in Ransomware Campaigns?
Known
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification
https://nvd.nist.gov/vuln/detail/CVE-2023-47246