CVE-2015-2993: SysAid
High severity, CVSS 7.5. EPSS: 55.1% chance of exploitation in the next 30 days.
SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to /createnewaccount or (2) write to arbitrary files via the fileName parameter to /userentry.
Affected products
- SysAid SysAid: up to and including 15.1
Published 2015-06-08. Last modified 2026-06-17.