CVE-2023-47246 is a critical path traversal vulnerability in SysAid On-Premise versions before 23.3.36, allowing unauthenticated attackers to achieve remote code execution by writing files to the Tomcat webroot. With a CVSS score of 9.8, it poses a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, notably by the Lace Tempest threat actor in Clop ransomware campaigns, and has garnered significant community discussion and media coverage, though public exploit code is limited to Nuclei templates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 23.3.36CPE matchmatch criteria | cpe:2.3:a:sysaid:sysaid:*:*:*:*:on-premises:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.