CVE-2023-47246

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
10/11/2023
Last modified:
20/12/2024

Description

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sysaid:sysaid:*:*:*:*:on-premises:*:*:* 23.3.36 (excluding)