Executive brief
SysAid On-Prem, a popular IT service management and help desk platform, contains a critical security flaw in its check-in processing system. An attacker can exploit this to steal sensitive files from the server or take over administrator accounts without needing any login credentials. This vulnerability has been observed being used in active attacks, posing a significant risk to organizational data and system control.
Technical details
SysAid On-Prem versions up to and including 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability (CWE-611). The flaw exists within the 'Checkin' processing functionality, where the application fails to properly restrict or validate XML external entity references in incoming requests. A remote, unauthenticated attacker can exploit this by sending a specially crafted XML payload to the server. Successful exploitation allows the attacker to read arbitrary files from the local file system and perform actions leading to the takeover of administrator accounts. This vulnerability is confirmed to be exploited in the wild and is addressed in version 24.4.60.
Affected products
- SysAid SysAid On-Prem <= 23.3.40
Timeline
- 2025-05-07: disclosed: Initial vulnerability disclosure and NVD publication
- 2025-07-22: kev added: CISA added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog
- 2025-07-22: advisory: CISA-ADP and VulnCheck provided enriched vulnerability data