CVE-2025-2776

Publication date

2025-05-07 14:50:40

Family

VulnCheck

State

PUBLISHED

Description

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.