Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Cheers co-creator and Friends director James Burrows dies at 85

Rich bassist Sixpence None dies at age 50

Dawn the Duck joins Scotland’s tartan army as unofficial mascot

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Important flaws to enable pre-rce on sysaid patch 4 on-premises version
Celebrities

Important flaws to enable pre-rce on sysaid patch 4 on-premises version

By May 7, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 7, 2025Ravi LakshmananVulnerability / IT Services

Cybersecurity researchers have disclosed multiple security flaws in the on-premises version of SysAid IT support software.

Vulnerabilities tracked as CVE-2025-2775, CVE-2025-2776, and CVE-2025-2777 are all called XML External Entity (XXE) injections.

This allows attackers to inject insecure XML entities into web applications, allowing server-side request forgery (SSRF) attacks, and in the worst case scenario, remote code execution.

Cybersecurity

According to Sina Kheirkhah and Jake Knott, researchers at WatchTowr Labs, the three vulnerabilities are explained:

CVE-2025-2775 and CVE-2025-2776- /mdm /checkin endpoints CVE-2025-2777 Pre-authenticated xxe- /lshw endpoints xxe

WatchTowr Labs described the vulnerability as trivial to exploit using specially created HTTP POST requests to the endpoint in question.

The successful exploitation of the flaw allows an attacker to retrieve a local file containing sensitive information, including Sysaid’s own “initaccount.cmd” file.

Armed with this information, the attacker was able to gain full administrative access to Sysaid as a user with particularly privileged administrators.

Worse, the XXE flaws can be chained with another operating system command injection vulnerability discovered by a third party to achieve remote code execution. Command injection issues are assigned the CVE identifier CVE-2025-2778.

Cybersecurity

All four vulnerabilities were fixed by Sysaid in early March 2025 with the release of on-premises version 24.4.60. A proof of concept (POC) exploit that combines four vulnerabilities is now available.

Due to the security flaws of Sysaid (CVE-2023-47246), it is essential for users to update their instances to the latest version, as previously exploited by ransomware actors like CL0P in zero-day attacks.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleDespite licensing suspension, UK arms exports are moving forward with Israeli press: Research | Israeli-Palestinian conflict news
Next Article The EU announces historic roadmap to end Russia’s energy dependence

Related Posts

Adria Arjona’s red Roberto Cavalli dress at the ‘Supergirl’ fan event

June 19, 2026

Jason Momoa’s daughter wears wired headphones as an accessory

June 19, 2026

Rama Dowaj Styles Upcycled Knicks Shirt by Claire Sullivan

June 18, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Cheers co-creator and Friends director James Burrows dies at 85

Rich bassist Sixpence None dies at age 50

Dawn the Duck joins Scotland’s tartan army as unofficial mascot

Prime Day Early Adult Toy Sale: Shop LELO, Womanizer and more

Trending Posts

Rich bassist Sixpence None dies at age 50

June 19, 2026

Adria Arjona’s red Roberto Cavalli dress at the ‘Supergirl’ fan event

June 19, 2026

Jason Momoa’s daughter wears wired headphones as an accessory

June 19, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.