ZeroHour

Vulnerabilities

30 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-2777
Unauthenticated XXE in SysAid On-Prem <= 23.3.40 Enables Admin Takeover

SysAid On-Prem versions 23.3.40 and earlier contain an unauthenticated XML External Entity (XXE) injection flaw (CWE-611) in the functionality that processes lshw (hardware inventory) data. Because the XML parser resolves external entities from network-supplied input without requiring authentication, a remote attacker can inject malicious entity definitions into lshw processing requests. Successful exploitation yields arbitrary file-read primitives and can be leveraged to take over an administrator account (CVSS 3.1: 9.8). All organizations running affected on-premises SysAid builds are in scope; cloud-hosted SysAid is not named in the advisory. Exploitation is likely in the wild: CISA has warned that SysAid flaws enabling remote file access and SSRF are under active attack, a public PoC has been released, and EPSS puts the 30-day exploitation probability at 72.2%.

Do: Upgrade SysAid On-Prem to a patched release newer than 23.3.40 as soon as possible (the vendor has patched this and related pre-auth flaws, per recent headlines). Until patched, minimize the server's internet exposure and restrict its outbound network access, since XXE exploitation can depend on the server resolving attacker-controlled external entities. Review logs for unexpected unauthenticated lshw/XML requests and for signs of administrator account changes or unusual file access.

9.872% PoC
  • SysAid On-Prem <= 23.3.40 (all on-premises builds up to and including 23.3.40)
largetens of thousands of on-prem deployments, with thousands of instances internet-exposed in public scans
CVE-2025-2776
+1 in the same advisory: …2775
Unauthenticated XXE in SysAid On-Prem Enables Admin Account Takeover

SysAid On-Prem, an IT service management (ITSM) platform, is vulnerable to an unauthenticated XML External Entity (XXE) flaw (CWE-611) in its Server URL processing functionality. Because the XML parser accepts attacker-controlled external entities without restriction, any remote attacker who can reach the vulnerable endpoint can trigger the flaw with no credentials and no user interaction. Successful exploitation gives the attacker arbitrary file-read primitives on the server, which can be leveraged to hijack an administrator account; public research (watchTowr) demonstrates chaining this XXE into pre-auth remote code execution, and related reporting notes SSRF and remote file access in active attacks. All SysAid On-Prem deployments running version 23.3.40 or earlier are affected. Exploitation is ongoing: CISA added CVE-2025-2776 to the Known Exploited Vulnerabilities catalog on 2025-07-22, and EPSS assigns a 64.4% probability of exploitation within 30 days.

Do: Upgrade all SysAid On-Prem installations to a release newer than 23.3.40 per the vendor's patched advisory, applying the other recently patched SysAid fixes as well since the public PoC chains this XXE with additional flaws into pre-auth RCE. Until patched, limit internet exposure of the SysAid server and check logs for XXE/SSRF activity and unexpected administrator logins. CISA's BOD 22-01 directive requires federal agencies to apply vendor mitigations or discontinue use of the product; the PoC is public and exploitation is confirmed, so treat this as urgent.

9.8
group max
64% KEV PoC
  • SysAid On-Prem <= 23.3.40
moderate≈2,000–10,000 internet-exposed SysAid On-Prem instances (thousands of customer organizations, many running the helpdesk portal on public endpoints)
CVE-2024-36394
+1 in the same advisory: …36393
SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

NVD description · AI analysis pending
9.81%
  • sysaid sysaid
CVE-2023-47247
In SysAid On-Premise before 23.3.34, there is an edge case in which an end user is able to delete a Knowledge Base article, aka bug 15102.

In SysAid On-Premise before 23.3.34, there is an edge case in which an end user is able to delete a Knowledge Base article, aka bug 15102.

NVD description · AI analysis pending
4.3<1%
  • sysaid sysaid
CVE-2023-33706
SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modifie

SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modified srID parameter to ShowMessage.jsp.

NVD description · AI analysis pending
6.5<1% PoC
  • sysaid sysaid
CVE-2023-47246
Unauthenticated Path Traversal RCE in SysAid On-Premise Server

CVE-2023-47246 is a critical (CVSS 9.8) path traversal flaw (CWE-22) in SysAid On-Premise before version 23.3.36 that allows an unauthenticated, network-located attacker to write attacker-controlled files into the Tomcat webroot of the SysAid server. Once a file is written into that webroot, it is executed by the Tomcat application server, resulting in remote code execution on the ITSM server. Because the flaw requires no authentication or user interaction, any internet-exposed SysAid On-Premise server is directly reachable, and compromise can lead to data theft and ransomware deployment; the Lace Tempest group behind the MOVEit attacks has exploited it, and ransomware use is known. Only SysAid On-Premise deployments are affected, and the vendor fixed the issue in version 23.3.36. The vulnerability is confirmed exploited in the wild, was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-13, and carries a 98.9% EPSS probability of exploitation within 30 days.

Do: Upgrade SysAid On-Premise to version 23.3.36 or later immediately, per the vendor's security notification. Because this is KEV-listed with known ransomware use by Lace Tempest, also inspect the Tomcat webroot and deployed webapps for unauthorized files (e.g., WAR files), review for unauthorized accounts and unusual processes, and check for signs of lateral movement on compromised hosts. Organizations unable to patch should apply mitigations per the vendor's instructions or discontinue use of the product, per the CISA required action.

9.899% KEV ransomware PoC
  • SysAid On-Premise (SysAid Server) before 23.3.36
moderate≈ a few thousand internet-exposed SysAid On-Premise servers (SysAid's overall customer base is on the order of tens of thousands of organizations, and only the…
CVE-2023-32225
+1 in the same advisory: …32226
Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype v

Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.

NVD description · AI analysis pending
7.2
group max
<1%
  • sysaid sysaid on-premises
CVE-2022-40325
+3 in the same advisory: …40324 …40323 …40322
SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262.

SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262.

NVD description · AI analysis pending
6.1<1%
  • sysaid help desk
CVE-2022-23170
SysAid - Okta SSO integration - was found vulnerable to XML External Entity Injection vulnerability.

SysAid - Okta SSO integration - was found vulnerable to XML External Entity Injection vulnerability. Any SysAid environment that uses the Okta SSO integration might be vulnerable. An unauthenticated attacker could exploit the XXE vulnerability by sending a malformed POST request to the identity provider endpoint. An attacker can extract the identity provider endpoint by decoding the SAMLRequest parameter's value and searching for the AssertionConsumerServiceURL parameter's value. It often allows an attacker to view files on the application server filesystem and interact with any back-end or external systems that the application can access. In some situations, an attacker can escalate an XXE attack to compromise the underlying server or other back-end infrastructure by leveraging the XXE vulnerability to perform server-side request forgery (SSRF) attacks.

NVD description · AI analysis pending
9.8<1%
  • sysaid okta sso
CVE-2022-22796
+4 in the same advisory: …23166 …22798 …22797 …23165
Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to:

Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, then click on the login button, and it will redirect you to /home.jsp without any authentication.

NVD description · AI analysis pending
9.8
group max
1%
  • sysaid sysaid
CVE-2021-43974
An issue was discovered in SysAid ITIL 20.4.74 b10.

An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, but does not respect the server-side setting that determines if anonymous users are allowed to register new accounts. Configuring the server-side setting to disable anonymous user registration only hides the client-side registration form. An attacker can still post registration data to create new accounts without prior authentication.

NVD description · AI analysis pending
5.31% PoC
  • sysaid itil
CVE-2021-43971
+2 in the same advisory: …43973 …43972
A SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to execute arbitrary SQL commands via

A SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to execute arbitrary SQL commands via the filterText parameter.

NVD description · AI analysis pending
8.8
group max
2% PoC
  • sysaid sysaid
CVE-2021-36721
Sysaid API User Enumeration - Attacker sending requests to specific api path without any authorization before 21.3.60 version could get users names from the LDA

Sysaid API User Enumeration - Attacker sending requests to specific api path without any authorization before 21.3.60 version could get users names from the LDAP server.

NVD description · AI analysis pending
5.3<1%
  • sysaid application programming interface
CVE-2021-31862
SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.

SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.

NVD description · AI analysis pending
6.14% PoC
  • sysaid sysaid
CVE-2021-30486
+1 in the same advisory: …30049
SysAid 20.3.64 b14 is affected by Blind and Stacker SQL injection via AssetManagementChart.jsp (GET computerID), AssetManagementChart.jsp (POST group1), AssetMa

SysAid 20.3.64 b14 is affected by Blind and Stacker SQL injection via AssetManagementChart.jsp (GET computerID), AssetManagementChart.jsp (POST group1), AssetManagementList.jsp (GET computerID or group1), or AssetManagementSummary.jsp (GET group1).

NVD description · AI analysis pending
8.8
group max
1% PoC
  • sysaid sysaid
CVE-2020-13168
SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.

SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • sysaid sysaid on-premises
  • sysaid sysaidsy on-premises
CVE-2020-10569
SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack.

SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticated access to upload files, which can be used to execute commands on the system by chaining it with a GhostCat attack. NOTE: This may be a duplicate of CVE-2020-1938

NVD description · AI analysis pending
9.83% PoC
  • sysaid on-premise