CVE-2025-2775

HIGH WAF: High
CVSS 7.5 Published: 2025-05-07
CWE-611

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.

WAF Coverage Analysis

XML External Entity (XXE) High WAF Coverage

OWASP: A05:2021 Security Misconfiguration

941xxx - XSS / XXE

Affected Software

VendorProductVersion
sysaidsysaidup to 23.3.40

References

Back to CVE Database