HIGH

CVE-2025-2775

Sysaid Sysaid 2025-05-07 CVSS v3.1
CVSS
7.5
KEV

Description

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.

Summary dbcve.org

SysAid On-Prem versions 23.3.40 and earlier contain an unauthenticated XXE vulnerability in the Checkin processing functionality. An attacker can exploit this by sending malicious XML with external entity references, potentially gaining administrative access or reading arbitrary files on the server.

Mitigation

Upgrade SysAid On-Prem to a version greater than 23.3.40. If immediate patching is not possible, disable or restrict XML processing in the Checkin functionality and implement strict input validation for XML payloads.

Proof of Concept

Weakness (CWE)

CWE-611 XML External Entity (XXE)

EPSS Score

42.95%
Probability of exploitation in next 30 days
98.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE