ZeroHour

CVE-2025-2775

KEV PoC moderate

XXE in SysAid On-Prem Checkin Processing Enables Admin Account Takeover

CISA: SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

CVSS 3.1
7.5 high
EPSS
43%p99
Published
()
KEV added
AI analysis

SysAid On-Prem contains an XML External Entity (XXE) injection flaw (CWE-611) in its Checkin processing functionality, where user-supplied XML is parsed without properly restricting external entity references. An attacker can submit crafted XML to the Checkin handler to trigger external entity resolution, gaining a file read primitive on the server and the ability to take over an administrator account. This can expose sensitive configuration data, such as credentials or files readable by the application, and hand the attacker administrative control of the SysAid instance. Organizations running self-hosted SysAid On-Prem are affected; SysAid's broader user base also includes SaaS deployments, which are not named in this advisory. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-22, indicating active exploitation, and its EPSS of 43% (99th percentile) points to a high near-term exploitation risk, though no public proof-of-concept is known and ransomware association is unknown.

What to do: Identify any self-hosted SysAid On-Prem instances in your environment and apply the vendor's patch per SysAid's instructions, or discontinue use if patching is not possible; federal agencies must follow BOD 22-01 deadlines. Until patched, restrict network access to the Checkin endpoint and review SysAid administrator accounts and application logs for signs of takeover or unexpected file access. Ransomware use is unknown, so treat any compromise with elevated urgency given this product's history of mass exploitation by ransomware groups.

Affected
SysAid On-Prem
Estimated exposure
moderateseveral thousand on-prem deployments (SysAid is a widely used mid-market ITSM platform; the on-prem installed base is a subset of its customer base) — SysAid serves a customer base in the thousands-to-tens-of-thousands of organizations, and the on-prem self-hosted portion — the only deployments exposed to this flaw — is plausibly in the low thousands to low tens of thousands, consistent…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.

CISA Known Exploited Vulnerability
Affected
SysAid SysAid On-Prem
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
sysaid
Products
sysaid
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news