Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

Edwards, Timberwolves overcome warriors in Game 3 to win a 2-1 series lead | Basketball News

“Difficult Certain Fire”: The guns remain silent, but will the India-Pakistan ceasefire be retained? | India and Pakistan tension news

Albania votes in general elections as Prime Minister Eddie Rama seeks a fourth term | Political News

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » Important flaws to enable pre-rce on sysaid patch 4 on-premises version
Identity

Important flaws to enable pre-rce on sysaid patch 4 on-premises version

userBy userMay 7, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 7, 2025Ravi LakshmananVulnerability / IT Services

Cybersecurity researchers have disclosed multiple security flaws in the on-premises version of SysAid IT support software.

Vulnerabilities tracked as CVE-2025-2775, CVE-2025-2776, and CVE-2025-2777 are all called XML External Entity (XXE) injections.

This allows attackers to inject insecure XML entities into web applications, allowing server-side request forgery (SSRF) attacks, and in the worst case scenario, remote code execution.

Cybersecurity

According to Sina Kheirkhah and Jake Knott, researchers at WatchTowr Labs, the three vulnerabilities are explained:

CVE-2025-2775 and CVE-2025-2776- /mdm /checkin endpoints CVE-2025-2777 Pre-authenticated xxe- /lshw endpoints xxe

WatchTowr Labs described the vulnerability as trivial to exploit using specially created HTTP POST requests to the endpoint in question.

The successful exploitation of the flaw allows an attacker to retrieve a local file containing sensitive information, including Sysaid’s own “initaccount.cmd” file.

Armed with this information, the attacker was able to gain full administrative access to Sysaid as a user with particularly privileged administrators.

Worse, the XXE flaws can be chained with another operating system command injection vulnerability discovered by a third party to achieve remote code execution. Command injection issues are assigned the CVE identifier CVE-2025-2778.

Cybersecurity

All four vulnerabilities were fixed by Sysaid in early March 2025 with the release of on-premises version 24.4.60. A proof of concept (POC) exploit that combines four vulnerabilities is now available.

Due to the security flaws of Sysaid (CVE-2023-47246), it is essential for users to update their instances to the latest version, as previously exploited by ransomware actors like CL0P in zero-day attacks.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleDespite licensing suspension, UK arms exports are moving forward with Israeli press: Research | Israeli-Palestinian conflict news
Next Article The EU announces historic roadmap to end Russia’s energy dependence
user
  • Website

Related Posts

Google pays $1.375 billion to Texas for fraudulent tracking and collection of biometric data

May 10, 2025

Germany shuts down more than $1.9 billion in laundry, seizing 34 million euros and 8TB of data using crypto

May 10, 2025

Breaking: EOL system dismantled in the US using 7,000 device proxy botnet IoT

May 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Edwards, Timberwolves overcome warriors in Game 3 to win a 2-1 series lead | Basketball News

“Difficult Certain Fire”: The guns remain silent, but will the India-Pakistan ceasefire be retained? | India and Pakistan tension news

Albania votes in general elections as Prime Minister Eddie Rama seeks a fourth term | Political News

Putin proposes Russia and Ukrainian talk directly in Istanbul on May 15 | News of the Russian-Ukrainian War

Trending Posts

Edwards, Timberwolves overcome warriors in Game 3 to win a 2-1 series lead | Basketball News

May 11, 2025

“Difficult Certain Fire”: The guns remain silent, but will the India-Pakistan ceasefire be retained? | India and Pakistan tension news

May 11, 2025

Albania votes in general elections as Prime Minister Eddie Rama seeks a fourth term | Political News

May 11, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Founders and Indie Hackers: Are potential buyers find your product at every stage of their search journey?

Google pays Texas with $1.375 billion in the country’s largest data privacy payment

Former Northvolt CEO Peter Carlson secures funding for the company’s new AI manufacturing startup after bankruptcy

Celsius founder Alex Masski has been sentenced to 12 years in a crypto fraud that was ordered to pay $48 million

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.