Unauthenticated XML External Entity Vulnerability in SysAid On-Prem Software
CVE-2025-2776
9.8CRITICAL
What is CVE-2025-2776?
The SysAid On-Premitory software is susceptible to an unauthenticated XML External Entity (XXE) vulnerability. This weakness exists in the Server URL processing functionality, potentially allowing an attacker to exploit it and gain unauthorized access to sensitive data and systems. As a result, an attacker may achieve administrator account takeover and perform unauthorized file read operations, raising serious concerns for data integrity and security within affected versions.
Affected Version(s)
SysAid On-Prem 0 <= 23.3.40
References
EPSS Score
16% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Sina Kheirkhah (@SinSinology)
Jake Knott
watchTowr