← Back to browse · API

CVE-2025-2777

Severity
CRITICAL
CVSS
9.3
EPSS
0.72268
Risk score
62.49
CISA KEV
No
PoC
No
Published
2025-05-07
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-13877, GHSA-HXV5-FPM3-VHQH
Products
SysAid:SysAid On-Prem 0 ≤23.3.40
Sources
euvd EUVD-2025-13877

Description

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.

References