SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
Vendor: SysAid
Product: SysAid On-Prem
Added: 2025-07-22
Due Date: 2025-08-12
Description:
SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.
Required Action:
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CWEs: