Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): cpe:2.3:a:sysaid:sysaid:22.3.35:*:*:*:on-premises:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2024-36394 |
SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Published: June 06, 2024; 5:15:14 AM -0400 |
V4.0:(not available) V3.1: 9.8 CRITICAL V2.0:(not available) |
CVE-2024-36393 |
SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Published: June 06, 2024; 5:15:14 AM -0400 |
V4.0:(not available) V3.1: 9.8 CRITICAL V2.0:(not available) |
CVE-2023-47247 |
In SysAid On-Premise before 23.3.34, there is an edge case in which an end user is able to delete a Knowledge Base article, aka bug 15102. Published: December 25, 2023; 2:15:09 AM -0500 |
V4.0:(not available) V3.1: 4.3 MEDIUM V2.0:(not available) |
CVE-2023-33706 |
SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modified srID parameter to ShowMessage.jsp. Published: November 23, 2023; 9:15:42 PM -0500 |
V4.0:(not available) V3.1: 6.5 MEDIUM V2.0:(not available) |