An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to upload an arbitrary file via the file parameter in the HTTP POST body. A successful request returns the absolute, server-side filesystem path of the uploaded file.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-01-11T19:20:43
Updated: 2024-08-04T04:10:17.149Z
Reserved: 2021-11-17T00:00:00
Link: CVE-2021-43973
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-01-11T20:15:07.667
Modified: 2024-11-21T06:30:06.773
Link: CVE-2021-43973
Redhat
No data.