CVE-2025-2777
CRITICAL
9.3
CVSS Severity Score
Vulnerability Description
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.
Affected Platforms (CPE)
📦
Sysaid
Sysaid
<= 23.3.40
