CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2023-47246

KEV · ransomware Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
KEV
Listed
ransomware
Class
other
CWE-22, CWE-22

Description

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

References

Status: profiled · ingested 2026-07-31T06:00:00.000Z