mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-29 20:39:28 +02:00
1.2 KiB
1.2 KiB
CVE-2025-2776
Description
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
POC
Reference
Github
- https://github.com/0xgh057r3c0n/SysAid-PreAuth-RCE-Chain
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/DevGreick/devgreick
- https://github.com/mrk336/From-EternalBlue-to-CVE-2025-2776-The-Evolution-of-an-SMB-Attack
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/packetinside/CISA_BOT
- https://github.com/ums91/CISA_BOT
- https://github.com/watchtowrlabs/watchTowr-vs-SysAid-PreAuth-RCE-Chain