Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modified srID parameter to ShowMessage.jsp.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sysaid Technologies SysAid 安全漏洞
Vulnerability Description
Sysaid Technologies SysAid是以色列Sysaid Technologies公司的一套IT服务管理解决方案。 Sysaid Technologies SysAid 23.2.15之前版本存在安全漏洞,该漏洞源于存在不安全的直接对象引用(IDOR)问题,允许攻击者通过修改EmailHtmlSourceIframe.jsp文件读取票证数据。
CVSS Information
N/A
Vulnerability Type
N/A