EXPOSURES › CVE-2025-2775
CVE-2025-2775
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
exploited-in-wildunpatched
SysAid On-Prem allowed XML External Entity Reference, enabling admin takeover and file reads
SysAid On-Prem, a Checkin processing feature, permitted XML External Entity Reference, leading to admin account takeover and file read primitives, impacting DIB's security posture.
Shame score — Critical vulnerability in a widely-used system, actively exploited, leading to potential unauthorized access and data breaches.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.