CVE-2025-2777
- EPSS 24.65%
- Veröffentlicht 07.05.2025 14:53:00
- Zuletzt bearbeitet 27.06.2025 14:35:46
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.
CVE-2025-2776
- EPSS 63.91%
- Veröffentlicht 07.05.2025 14:50:40
- Zuletzt bearbeitet 27.10.2025 16:58:51
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
CVE-2025-2775
- EPSS 69.79%
- Veröffentlicht 07.05.2025 14:43:23
- Zuletzt bearbeitet 27.10.2025 16:58:55
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.
CVE-2024-36394
- EPSS 0.15%
- Veröffentlicht 06.06.2024 09:15:14
- Zuletzt bearbeitet 21.11.2024 09:22:05
SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-36393
- EPSS 0.26%
- Veröffentlicht 06.06.2024 09:15:14
- Zuletzt bearbeitet 21.11.2024 09:22:05
SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-27775
- EPSS 0.13%
- Veröffentlicht 28.03.2024 13:15:47
- Zuletzt bearbeitet 21.11.2024 09:05:02
SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's NTLMv2 hash
CVE-2023-47247
- EPSS 0.06%
- Veröffentlicht 25.12.2023 07:15:09
- Zuletzt bearbeitet 21.11.2024 08:30:02
In SysAid On-Premise before 23.3.34, there is an edge case in which an end user is able to delete a Knowledge Base article, aka bug 15102.
CVE-2023-33706
- EPSS 0.08%
- Veröffentlicht 24.11.2023 02:15:42
- Zuletzt bearbeitet 21.11.2024 08:05:53
SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modified srID parameter to ShowMessage.jsp.
CVE-2023-47246
- EPSS 94.35%
- Veröffentlicht 10.11.2023 06:15:30
- Zuletzt bearbeitet 31.10.2025 14:38:24
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
- EPSS 0.44%
- Veröffentlicht 12.05.2022 20:15:15
- Zuletzt bearbeitet 21.11.2024 06:48:06
Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/tinymce/examples/index.html" path. in the "Insert/Edit Embedded Media" window Choose Type : iFrame and File/URL : [here is the LFI...