Critical severity9.3CISA KEVNVD Advisory· Published May 7, 2025· Updated Jun 17, 2026
CVE-2025-2776
CVE-2025-2776
Description
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: 0
Patches
Vulnerability mechanics
References
3- labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket/nvdExploitThird Party Advisory
- documentation.sysaid.com/docs/24-40-60nvdRelease Notes
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.