📦 Sysaid

by Sysaid

🔍 What is Sysaid?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-2775

CRITICAL CVSS 9.3 May 7, 2025

SysAid On-Prem versions up to 23.3.40 contain an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality. This allows attackers to read files from the server an...

CVE-2025-2777

CRITICAL CVSS 9.3 May 7, 2025

SysAid On-Prem versions up to 23.3.40 contain an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality. This allows attackers to read arbitrary files from the se...

CVE-2024-36393

CRITICAL CVSS 9.9 Jun 6, 2024

This SQL injection vulnerability in SysAid allows attackers to execute arbitrary SQL commands on the database. It affects organizations using vulnerable versions of SysAid software, potentially exposi...

CVE-2022-22796

HIGH CVSS 7.0 May 12, 2022

This authentication bypass vulnerability in SysAid allows attackers to access the system without valid credentials by navigating through specific JSP pages. Organizations using vulnerable versions of ...

CVE-2021-43971

HIGH CVSS 8.8 Jan 11, 2022

This SQL injection vulnerability in SysAid ITIL allows authenticated attackers to execute arbitrary SQL commands via the filterText parameter in the /mobile/SelectUsers.jsp endpoint. Attackers can pot...

CVE-2021-43973

HIGH CVSS 8.8 Jan 11, 2022

This vulnerability allows authenticated remote attackers to upload arbitrary files to SysAid ITIL servers via the /UploadPsIcon.jsp endpoint. Successful exploitation reveals the server-side file path,...

CVE-2021-30486

HIGH CVSS 8.8 Jul 22, 2021

This SQL injection vulnerability in SysAid allows attackers to execute arbitrary SQL commands through multiple AssetManagement endpoints. It affects SysAid On-Premise installations, potentially enabli...