CVE-2017-9376: Input Validation
Published Mar 25, 2019
·Updated
ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.
Affected Software
1 affected component
ZohoCorp ManageEngine ServiceDesk Plus<9.3
Event History
Mar 25, 2019
CVE Published
via MITRE·03:53 PM
Data Sourced
via MITRE·03:53 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9376?
The severity of CVE-2017-9376 is medium with a score of 6.5.
2
What is the affected software for CVE-2017-9376?
The affected software for CVE-2017-9376 is ManageEngine ServiceDesk Plus version up to 9.3.
3
What is the vulnerability type of CVE-2017-9376?
The vulnerability type of CVE-2017-9376 is local file inclusion.
4
How can I exploit CVE-2017-9376?
Exploiting CVE-2017-9376 requires exploiting a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.
5
How can I fix CVE-2017-9376?
To fix CVE-2017-9376, you should update ManageEngine ServiceDesk Plus to version 9.3.14 or later.