First published: Wed May 07 2025(Updated: )
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
Credit: disclosure@vulncheck.com
Affected Software | Affected Version | How to fix |
---|---|---|
SysAid | <=23.3.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2776 has a high severity due to its potential for administrator account takeover.
To fix CVE-2025-2776, upgrade SysAid On-Prem to version 23.3.41 or later.
CVE-2025-2776 is an unauthenticated XML External Entity (XXE) vulnerability.
SysAid On-Prem versions up to and including 23.3.40 are affected by CVE-2025-2776.
Yes, CVE-2025-2776 can allow attackers to read sensitive files, leading to data exposure.