An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, high privileged user to write arbitrary files into sensitive directories of ITSM server.
References
| Link | Resource |
|---|---|
| https://forums.ivanti.com/s/article/Security-Advisory-May-2024 | Vendor Advisory |
| https://forums.ivanti.com/s/article/Security-Advisory-May-2024 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-05-31 18:15
Updated : 2025-06-30 18:28
NVD link : CVE-2024-22060
Mitre link : CVE-2024-22060
CVE.ORG link : CVE-2024-22060
JSON object : View
Products Affected
ivanti
- neurons_for_itsm
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
