Files
CVEs-PoC/2025/CVE-2025-2777.md
T
2025-09-29 21:09:30 +02:00

940 B

CVE-2025-2777

Description

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.

POC

Reference

Github