CRITICAL

CVE-2025-2776

Sysaid Sysaid 2025-05-07 CVSS v3.1
CVSS
9.8
KEV

Description

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

Summary dbcve.org

SysAid On-Prem versions <= 23.3.40 contain an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality. This allows remote attackers to read arbitrary files on the server and potentially takeover administrator accounts.

Mitigation

Upgrade SysAid On-Prem to a version greater than 23.3.40, or apply the vendor-supplied patch to remediate the XXE vulnerability in Server URL processing.

Proof of Concept

Weakness (CWE)

CWE-611 XML External Entity (XXE)

EPSS Score

64.4%
Probability of exploitation in next 30 days
99.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE