CVE-2017-11512

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
08/11/2017
Last modified:
20/04/2025

Description

The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:manageengine:servicedesk:9.3.9328:*:*:*:*:*:*:*