VYPR
High severity7.5NVD Advisory· Published Nov 8, 2017· Updated May 13, 2026

CVE-2017-11511

CVE-2017-11511

Description

The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath parameter for the download-file URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.

Affected products

2
  • Zoho/ManageEngine ServiceDeskv5
    Range: 9.3.9328
  • cpe:2.3:a:manageengine:servicedesk:9.3.9328:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.