Unauthenticated XML External Entity Vulnerability in SysAid On-Prem Software
CVE-2025-2776

9.8CRITICAL

Key Information:

Vendor

Sysaid

Vendor
CVE Published:
7 May 2025

Badges

👾 Exploit Exists🟣 EPSS 16%

What is CVE-2025-2776?

The SysAid On-Premitory software is susceptible to an unauthenticated XML External Entity (XXE) vulnerability. This weakness exists in the Server URL processing functionality, potentially allowing an attacker to exploit it and gain unauthorized access to sensitive data and systems. As a result, an attacker may achieve administrator account takeover and perform unauthorized file read operations, raising serious concerns for data integrity and security within affected versions.

Affected Version(s)

SysAid On-Prem 0 <= 23.3.40

References

EPSS Score

16% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sina Kheirkhah (@SinSinology)
Jake Knott
watchTowr
.