CVE-2025-2775

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.

  • Published May 7, 2025
  • CVSS 7.5 high
  • 42.6% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • Public exploit code is available

Affected software

CVE-2025-2775 at the National Vulnerability Database