Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-2775 PoC — SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection

Source
Associated Vulnerability
Title:SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection (CVE-2025-2775)
Description:SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.
Description
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.
File Snapshot

id: CVE-2025-2775 info: name: SysAid On-Prem <= 23.3.40 - XML External Entity author: johnk3r ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →