VYPR
Medium severity4.9NVD Advisory· Published May 31, 2024· Updated Jun 17, 2026

CVE-2024-22060

CVE-2024-22060

Description

An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, high privileged user to write arbitrary files into sensitive directories of ITSM server.

Affected products

3
  • Ivanti/ITSMcpe-rescue
    Range: 2023.3
  • Ivanti/Neurons For Itsmllm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • cpe:2.3:a:ivanti:neurons_for_itsm:*:*:*:*:*:*:*:*range: <2023.3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.