First published: Mon Mar 25 2019(Updated: )
ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Servicedesk Plus | <9.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-9376 is medium with a score of 6.5.
The affected software for CVE-2017-9376 is ManageEngine ServiceDesk Plus version up to 9.3.
The vulnerability type of CVE-2017-9376 is local file inclusion.
Exploiting CVE-2017-9376 requires exploiting a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.
To fix CVE-2017-9376, you should update ManageEngine ServiceDesk Plus to version 9.3.14 or later.