National Cyber Warfare Foundation (NCWF)

SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version


0 user ratings
2025-05-07 11:48:32
milo
Blue Team (CND)
Cybersecurity researchers have disclosed multiple security flaw in the on-premise version of SysAid IT support software that could be exploited to achieve pre-authenticated remote code execution with elevated privileges.
The vulnerabilities, tracked as CVE-2025-2775, CVE-2025-2776, and CVE-2025-2777, have all been described as XML External Entity (XXE) injections, which occur when an attacker is



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/05/sysaid-patches-4-critical-flaws.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.