Loading HuntDB...

GHSA-g3m4-2wr6-2q64

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.

Related CVEs

Key Information

GHSA ID
GHSA-g3m4-2wr6-2q64
Published
May 7, 2025 3:31 PM
Last Modified
May 7, 2025 3:31 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 25, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.