An unrestricted file upload vulnerability in ...
High severity
Unreviewed
Published
Jan 12, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Jan 11, 2022
Published to the GitHub Advisory Database
Jan 12, 2022
Last updated
Feb 3, 2023
An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to upload an arbitrary file via the file parameter in the HTTP POST body. A successful request returns the absolute, server-side filesystem path of the uploaded file.
References