PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2017-11512

7.5
CVSS
Description

The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.

Attack Vector
-
Privileges Req.
-
User Interaction
-
manageengine servicedesk
Updated Sep 18, 2026View on NVD →
S4E scanner

CVE history: manageengine servicedesk

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →