CVE-2015-2997: SysAid
Medium severity, CVSS 5.0. EPSS: 57% chance of exploitation in the next 30 days.
SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getAgentLogFile, as demonstrated by a large directory traversal sequence, which reveals the installation path in an error message.
Affected products
- SysAid SysAid: up to and including 15.1
Published 2015-06-08. Last modified 2026-06-17.