← Back to browse · API

CVE-2023-46808

Severity
CRITICAL
CVSS
9.9
EPSS
0.02001
Risk score
40.3
CISA KEV
No
PoC
No
Published
2024-03-31
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2023-50974, GHSA-6GXV-CH26-86WV
Products
Ivanti:ITSM 2023.3 ≤2023.3
Sources
euvd EUVD-2023-50974

Description

An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. Successful exploitation may lead to execution of commands in the context of non-root user.

References