Tag: Pre-Auth RCE

SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version
News

SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version

Multiple security flaws in the on-premise SysAid IT assistance software have been discovered by cybersecurity experts. These flaws might be used to obtain elevated privileges and pre-authenticated remote code execution. The vulnerabilities have been identified as XML External Entity (XXE) injections, which happen when an attacker successfully tampers with an application's ability to parse XML input. They are tracked as CVE-2025-2775, CVE-2025-2776, and CVE-2025-2777. Attackers may then be able to perform a Server-Side Request Forgery (SSRF) attack and, in the worst situations, remote code execution by injecting malicious XML entities into the web application. WatchTowr Labs researchers Sina Kheirkhah and Jake Knott have described the three vulnerabilities read more about SysAid P...