An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. Successful exploitation may lead to execution of commands in the context of non-root user. 
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2023-50974 | An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. Successful exploitation may lead to execution of commands in the context of non-root user. | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-02T20:53:21.657Z
Reserved: 2023-10-27T01:00:13.400Z
Link: CVE-2023-46808
Updated: 2024-08-02T20:53:21.657Z
Status : Modified
Published: 2024-03-31T02:15:08.757
Modified: 2024-11-21T08:29:21.070
Link: CVE-2023-46808
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD