Critical CVSS 9.3

Overview

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

Risk analysis

This vulnerability is rated 🔴 CRITICAL.

  • CVSS: 9.3 (CRITICAL)
  • Detected tags: xxe (tag impact: MODERATE)

Recommended actions:

  • Disable external entities in XML parsers; use safe libraries.

Recommended tools

Tags