Junglewise Threat Intelligence

CVE-2025-2776: SysAid On-Prem XXE in Server URL processing

CVE-2025-2776 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-07-22

Executive brief

SysAid On-Prem, a popular IT service management and help desk platform, contains a critical security flaw in how it handles server configuration data. An attacker can exploit this to take over administrator accounts or steal sensitive files from the server without needing any login credentials. This vulnerability is known to be actively exploited in the wild, posing a significant risk of full system compromise and data theft.

Technical details

An unauthenticated XML External Entity (XXE) vulnerability exists in SysAid On-Prem versions up to and including 23.3.40. The flaw is located within the Server URL processing functionality, where the application fails to properly restrict or sanitize XML external entity references (CWE-611). A remote, unauthenticated attacker can exploit this by sending a specially crafted XML payload to the vulnerable endpoint. Successful exploitation allows the attacker to read arbitrary files from the server's file system or perform an administrator account takeover. This vulnerability has been observed in active exploitation, and users are advised to upgrade to a patched version (e.g., 24.40.60) as per vendor release notes.

Affected products

  • SysAid SysAid On-Prem <= 23.3.40

Timeline

  • 2025-05-07: disclosed: Initial CVE publication
  • 2025-07-22: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-08-12: other: CISA due date for remediation

Related threats