The ManageEngine ServiceDesk 9.3.9328 is vulnerable to...
High severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Apr 20, 2025
Description
Published by the National Vulnerability Database
Nov 8, 2017
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Apr 20, 2025
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath parameter for the download-file URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.
References