← Back to browse · API

CVE-2025-2776

Severity
CRITICAL
CVSS
9.3
EPSS
0.63999
Risk score
84.6
CISA KEV
Yes
PoC
No
Published
2025-07-22
Modified
2025-07-22
First seen
2026-08-07
Aliases
EUVD-2025-13875, GHSA-HVRH-GFRR-FGC9
Products
SysAid:SysAid On-Prem, SysAid:SysAid On-Prem 0 ≤23.3.40
Sources
euvd EUVD-2025-13875
cisa.gov CVE-2025-2776

Description

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

References