Sysaid
by Sysaid
CVEs (38)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-47246 | Cri | 0.90 | 9.8 | 0.99 | KEV | Nov 10, 2023 | In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023. | |
| CVE-2025-2776 | Cri | 0.78 | 9.3 | 0.64 | KEV | May 7, 2025 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives. | |
| CVE-2025-2775 | Cri | 0.77 | 9.3 | 0.43 | KEV | May 7, 2025 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives. | |
| CVE-2025-2777 | Cri | 0.67 | 9.3 | 0.72 | May 7, 2025 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives. | ||
| CVE-2024-36393 | Cri | 0.64 | 9.9 | 0.00 | Jun 6, 2024 | SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | ||
| CVE-2023-32225 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2023 | Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method. | ||
| CVE-2020-10569 | Cri | 0.64 | 9.8 | 0.03 | Apr 21, 2020 | SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticated access to upload files, which can be used to execute commands on the system by chaining it with a GhostCat attack. NOTE: This… | ||
| CVE-2024-36394 | Cri | 0.59 | 9.1 | 0.01 | Jun 6, 2024 | SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | ||
| CVE-2021-43973 | Hig | 0.57 | 8.8 | 0.02 | Jan 11, 2022 | An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to upload an arbitrary file via the file parameter in the HTTP POST body. A successful request returns the absolute, server-side filesystem path of… | ||
| CVE-2021-43971 | Hig | 0.57 | 8.8 | 0.02 | Jan 11, 2022 | A SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to execute arbitrary SQL commands via the filterText parameter. | ||
| CVE-2021-30486 | Hig | 0.57 | 8.8 | 0.01 | Jul 22, 2021 | SysAid 20.3.64 b14 is affected by Blind and Stacker SQL injection via AssetManagementChart.jsp (GET computerID), AssetManagementChart.jsp (POST group1), AssetManagementList.jsp (GET computerID or group1), or AssetManagementSummary.jsp (GET group1). | ||
| CVE-2023-32226 | Hig | 0.54 | 8.3 | 0.01 | Jul 30, 2023 | Sysaid - CWE-552: Files or Directories Accessible to External Parties - Authenticated users may exfiltrate files from the server via an unspecified method. | ||
| CVE-2024-27775 | Hig | 0.47 | 7.2 | 0.01 | Mar 28, 2024 | SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's NTLMv2 hash | ||
| CVE-2022-22796 | Hig | 0.46 | 7.0 | 0.01 | May 12, 2022 | Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, then click on the login button, and it will redirect you to /home.jsp without any authentication. | ||
| CVE-2022-22798 | Med | 0.44 | 6.8 | 0.01 | May 12, 2022 | Sysaid – Pro Plus Edition, SysAid Help Desk Broken Access Control v20.4.74 b10, v22.1.20 b62, v22.1.30 b49 - An attacker needs to log in as a guest after that the system redirects him to the service portal or EndUserPortal.JSP, then he needs to change the path in the URL to… | ||
| CVE-2023-33706 | Med | 0.42 | 6.5 | 0.01 | Nov 24, 2023 | SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modified srID parameter to ShowMessage.jsp. | ||
| CVE-2021-43972 | Med | 0.42 | 6.5 | 0.01 | Jan 11, 2022 | An unrestricted file copy vulnerability in /UserSelfServiceSettings.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to copy arbitrary files on the server filesystem to the web root (with an arbitrary filename) via the tempFile and fileName parameters in the… | ||
| CVE-2022-23166 | Med | 0.40 | 6.1 | 0.01 | May 12, 2022 | Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/tinymce/examples/index.html" path. in the "Insert/Edit Embedded Media" window Choose Type : iFrame and File/URL : [here is the LFI] Solution: Update to… | ||
| CVE-2021-31862 | Med | 0.40 | 6.1 | 0.04 | Oct 29, 2021 | SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication. | ||
| CVE-2021-30049 | Med | 0.40 | 6.1 | 0.02 | Jul 22, 2021 | SysAid 20.3.64 b14 is affected by Cross Site Scripting (XSS) via a /KeepAlive.jsp?stamp= URI. |
- risk 0.90cvss 9.8epss 0.99
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
- risk 0.78cvss 9.3epss 0.64
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
- risk 0.77cvss 9.3epss 0.43
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.
- risk 0.67cvss 9.3epss 0.72
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.
- risk 0.64cvss 9.9epss 0.00
SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- risk 0.64cvss 9.8epss 0.01
Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.
- risk 0.64cvss 9.8epss 0.03
SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticated access to upload files, which can be used to execute commands on the system by chaining it with a GhostCat attack. NOTE: This…
- risk 0.59cvss 9.1epss 0.01
SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- risk 0.57cvss 8.8epss 0.02
An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to upload an arbitrary file via the file parameter in the HTTP POST body. A successful request returns the absolute, server-side filesystem path of…
- risk 0.57cvss 8.8epss 0.02
A SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to execute arbitrary SQL commands via the filterText parameter.
- risk 0.57cvss 8.8epss 0.01
SysAid 20.3.64 b14 is affected by Blind and Stacker SQL injection via AssetManagementChart.jsp (GET computerID), AssetManagementChart.jsp (POST group1), AssetManagementList.jsp (GET computerID or group1), or AssetManagementSummary.jsp (GET group1).
- risk 0.54cvss 8.3epss 0.01
Sysaid - CWE-552: Files or Directories Accessible to External Parties - Authenticated users may exfiltrate files from the server via an unspecified method.
- risk 0.47cvss 7.2epss 0.01
SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's NTLMv2 hash
- risk 0.46cvss 7.0epss 0.01
Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, then click on the login button, and it will redirect you to /home.jsp without any authentication.
- risk 0.44cvss 6.8epss 0.01
Sysaid – Pro Plus Edition, SysAid Help Desk Broken Access Control v20.4.74 b10, v22.1.20 b62, v22.1.30 b49 - An attacker needs to log in as a guest after that the system redirects him to the service portal or EndUserPortal.JSP, then he needs to change the path in the URL to…
- risk 0.42cvss 6.5epss 0.01
SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modified srID parameter to ShowMessage.jsp.
- risk 0.42cvss 6.5epss 0.01
An unrestricted file copy vulnerability in /UserSelfServiceSettings.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to copy arbitrary files on the server filesystem to the web root (with an arbitrary filename) via the tempFile and fileName parameters in the…
- risk 0.40cvss 6.1epss 0.01
Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/tinymce/examples/index.html" path. in the "Insert/Edit Embedded Media" window Choose Type : iFrame and File/URL : [here is the LFI] Solution: Update to…
- risk 0.40cvss 6.1epss 0.04
SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.
- risk 0.40cvss 6.1epss 0.02
SysAid 20.3.64 b14 is affected by Cross Site Scripting (XSS) via a /KeepAlive.jsp?stamp= URI.
Page 1 of 2