SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
2025-05-07T15:15:57.573
2025-10-27T16:58:51.230
Analyzed
CVSSv3.1: 9.3 (CRITICAL)