CRITICAL
CVE-2025-2776
CVSS
9.8
KEV
Description
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
Summary dbcve.org
SysAid On-Prem versions <= 23.3.40 contain an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality. This allows remote attackers to read arbitrary files on the server and potentially takeover administrator accounts.
Mitigation
Upgrade SysAid On-Prem to a version greater than 23.3.40, or apply the vendor-supplied patch to remediate the XXE vulnerability in Server URL processing.
Weakness (CWE)
CWE-611
XML External Entity (XXE)
EPSS Score
64.4%
Probability of exploitation in next 30 days
99.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.