HIGH
CVE-2025-2775
CVSS
7.5
KEV
Description
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.
Summary dbcve.org
SysAid On-Prem versions 23.3.40 and earlier contain an unauthenticated XXE vulnerability in the Checkin processing functionality. An attacker can exploit this by sending malicious XML with external entity references, potentially gaining administrative access or reading arbitrary files on the server.
Mitigation
Upgrade SysAid On-Prem to a version greater than 23.3.40. If immediate patching is not possible, disable or restrict XML processing in the Checkin functionality and implement strict input validation for XML payloads.
Weakness (CWE)
CWE-611
XML External Entity (XXE)
EPSS Score
42.95%
Probability of exploitation in next 30 days
98.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.