CVE-2025-2775: SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2025-07-22. EPSS: 42.6% chance of exploitation in the next 30 days.
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.
Affected products
- SysAid SysAid: up to and including 23.3.40
Published 2025-05-07. Last modified 2026-06-17.