CVE-2025-2776: SysAid On-Prem <= 23.3.40 - XML External Entity

CVE-2025-2776: SysAid On-Prem <= 23.3.40 - XML External Entity-渗透云记 - 专注于网络安全与技术分享
CVE-2025-2776: SysAid On-Prem <= 23.3.40 - XML External Entity
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2025-2776: SysAid On-Prem <= 23.3.40 – XML External Entity

漏洞描述

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (xxe) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享