Vulnerabilities > Sysaid > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-01-11 CVE-2021-43974 Missing Authentication for Critical Function vulnerability in Sysaid Itil 20.4.74
An issue was discovered in SysAid ITIL 20.4.74 b10.
network
low complexity
sysaid CWE-306
5.3
2021-12-14 CVE-2021-36721 Unspecified vulnerability in Sysaid Application Programming Interface
Sysaid API User Enumeration - Attacker sending requests to specific api path without any authorization before 21.3.60 version could get users names from the LDAP server.
network
low complexity
sysaid
5.3
2021-10-29 CVE-2021-31862 Cross-site Scripting vulnerability in Sysaid 20.4.74
SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.
network
low complexity
sysaid CWE-79
6.1
2021-07-22 CVE-2021-30049 Cross-site Scripting vulnerability in Sysaid 20.3.64
SysAid 20.3.64 b14 is affected by Cross Site Scripting (XSS) via a /KeepAlive.jsp?stamp= URI.
network
low complexity
sysaid CWE-79
6.1
2020-10-02 CVE-2020-13168 Cross-site Scripting vulnerability in Sysaid On-Premises and Sysaidsy On-Premises
SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.
network
low complexity
sysaid CWE-79
6.1