An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, but does not respect the server-side setting that determines if anonymous users are allowed to register new accounts. Configuring the server-side setting to disable anonymous user registration only hides the client-side registration form. An attacker can still post registration data to create new accounts without prior authentication.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T04:10:17.125Z

Reserved: 2021-11-17T00:00:00

Link: CVE-2021-43974

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-01-11T20:15:07.710

Modified: 2024-11-21T06:30:06.927

Link: CVE-2021-43974

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.