vendor:
SysAid On-Premise
by:
Bernhard Mueller
8,8
CVSS
HIGH
Arbitrary File Disclosure
200
CWE
Product Name: SysAid On-Premise
Affected Version From: < 14.4.2
Affected Version To: 14.4.2
Patch Exists: YES
Related CWE: N/A
CPE: a:sysaid:sysaid_on-premise
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2014
SysAid Server Arbitrary File Disclosure
SysAid Server is vulnerable to an unauthenticated file disclosure attack that allows an anonymous attacker to read arbitrary files on the system. An attacker exploiting this issue can compromise SysAid user accounts and gain access to important system files. When SysAid is configured to use LDAP authentication it is possible to gain read access to the entire Active Directory or obtain domain admin privileges.
Mitigation:
Upgrade to version 14.4.2.