CVE-2020-13168: SysAid On-Premises

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.

Affected products

  • SysAid SysAid On-Premises: version 5.0 only; version 5.5.06 only; version 5.6 only; version 6.0.9 only; version 6.5 only; version 7.0 only; …
  • SysAid Sysaidsy On-Premises: version 20.1.11 only

Published 2020-10-02. Last modified 2026-06-17.