CVE-2025-43716 | Ivanti LANDesk Management Suite up to 4.2-1.9 /client/index.php incorrect behavior order: validate before canonicalize
A vulnerability was found in Ivanti LANDesk Management Suite up to 4.2-1.9 and classified as problematic. Affected by this issue is some unknown functionality of the file /client/index.php. The manipulation with the input %3F.php leads to incorrect behavior order: validate before canonicalize. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is handled as CVE-2025-43716. The attack may be launched remotely. Furthermore, there is an exploit available.