First published: Mon Jun 08 2015(Updated: )
SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to /createnewaccount or (2) write to arbitrary files via the fileName parameter to /userentry.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sysaid On-Premises | <=15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2993 is considered a high severity vulnerability due to the potential for remote attackers to gain unauthorized access and escalate privileges.
To fix CVE-2015-2993, upgrade to SysAid Help Desk version 15.2 or later, which includes a patch for the vulnerability.
CVE-2015-2993 allows remote attackers to create administrator accounts and write to arbitrary files by exploiting insufficient access controls.
SysAid Help Desk versions prior to 15.2 are affected by CVE-2015-2993.
Organizations using affected versions of SysAid Help Desk are at risk of exploitation through CVE-2015-2993.