Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-2776


SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.


Published

2025-05-07T15:15:57.573

Last Modified

2025-10-27T16:58:51.230

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.3 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sysaid sysaid ≤ 23.3.40 Yes

References