A critical vulnerability, CVE-2025-2775, has been identified in SysAid On-Prem versions ≤ 23.3.40, exposing the platform to an unauthenticated XML External Entity (XXE) injection flaw within the Checkin processing functionality. This vulnerability allows remote attackers to exploit XML parsing behavior to read arbitrary files from the server or gain access to sensitive information, including administrator credentials. Successful exploitation can lead to full administrative account takeover and further system compromise. SysAid has released a security advisory urging immediate patching. The IONIX research team verified the vulnerability’s impact through exploit simulation, detailed in this post.
References:

