← Back to CVE List

CVE-2021-28023

Published: 2021-11-08T15:15Z
Last Modified: 2024-11-21T05:58Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious user to execute JSP code by uploading a zip that extracts files in relative paths. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt