CVE-2025-2776
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
- EPSS probability
- 64.40%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-611
- Published
- 2025-05-07
- Last modified
- 2025-11-19
Affected products
- SysAid SysAid On-Prem
Weakness type
Related vulnerabilities
- CVE-2025-58360 — GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
- CVE-2025-2775 — SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
- CVE-2025-68493 — Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component
- CVE-2025-11700 — N-central Multiple XXE Injection Vulnerabilities
- CVE-2025-2777 — SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
- CVE-2025-30220 — GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling
- CVE-2026-32251 — Tolgee has an XXE Injection in Translation Import
- CVE-2025-49535 — ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)