CVE-2025-2776
SysAid SysAid On-Prem
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
- CVSS
- 9.8
- EPSS
- 64.0% 99.1% percentile
- CISA KEV
- Listed
- Published
- 2025.05.08