Unrated severityNVD Advisory· Published Nov 8, 2021· Updated Aug 3, 2024
CVE-2021-28023
CVE-2021-28023
Description
Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious user to execute JSP code by uploading a zip that extracts files in relative paths.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- ServiceTonic/Helpdesk softwaredescription
- Range: <9.0.35937
Patches
Vulnerability mechanics
References
2- www.servicetonic.commitrex_refsource_MISC
- www.srlabs.de/bites/chaining-three-zero-day-exploits-in-itsm-software-servicetonic-for-remote-code-executionmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.