EUVD-2025-13875
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 22 Jul 2025. Evidence sources: cisa_kev.
- ENISA score
- 9.3 · CVSS 3.1
- Advisory evidence
- 2 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_ncscnl · NCSC-2025-0144Kwetsbaarheden verholpen in SysAid On-Prem
