CVE-2025-2775
KEV PoC moderateXXE in SysAid On-Prem Checkin Processing Enables Admin Account Takeover
CISA: SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
SysAid On-Prem contains an XML External Entity (XXE) injection flaw (CWE-611) in its Checkin processing functionality, where user-supplied XML is parsed without properly restricting external entity references. An attacker can submit crafted XML to the Checkin handler to trigger external entity resolution, gaining a file read primitive on the server and the ability to take over an administrator account. This can expose sensitive configuration data, such as credentials or files readable by the application, and hand the attacker administrative control of the SysAid instance. Organizations running self-hosted SysAid On-Prem are affected; SysAid's broader user base also includes SaaS deployments, which are not named in this advisory. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-22, indicating active exploitation, and its EPSS of 43% (99th percentile) points to a high near-term exploitation risk, though no public proof-of-concept is known and ransomware association is unknown.
What to do: Identify any self-hosted SysAid On-Prem instances in your environment and apply the vendor's patch per SysAid's instructions, or discontinue use if patching is not possible; federal agencies must follow BOD 22-01 deadlines. Until patched, restrict network access to the Checkin endpoint and review SysAid administrator accounts and application logs for signs of takeover or unexpected file access. Ransomware use is unknown, so treat any compromise with elevated urgency given this product's history of mass exploitation by ransomware groups.
| SysAid On-Prem | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.
- Affected
- SysAid SysAid On-Prem
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- sysaid
- Products
- sysaid
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N