CVE-2023-47246: SysAid Server Path Traversal Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2023-11-13. EPSS: 98.9% chance of exploitation in the next 30 days.
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
Affected products
- SysAid SysAid: before 23.3.36 (fixed in 23.3.36)
Published 2023-11-10. Last modified 2026-07-31.