Filtered by vendor Sysaid
                         Subscriptions
                    
                    
                
                        Filtered by product Sysaid
                         Subscriptions
                    
                    
                
                    Total
                    30 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v3.1 | 
|---|---|---|---|---|
| CVE-2025-2776 | 1 Sysaid | 1 Sysaid | 2025-10-22 | 9.3 Critical | 
| SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives. | ||||
| CVE-2025-2775 | 1 Sysaid | 1 Sysaid | 2025-10-22 | 9.3 Critical | 
| SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives. | ||||
| CVE-2023-47246 | 1 Sysaid | 2 Sysaid, Sysaid On-premises | 2025-10-22 | 9.8 Critical | 
| In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023. | ||||
| CVE-2024-27775 | 1 Sysaid | 1 Sysaid | 2025-07-13 | 7.2 High | 
| SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's NTLMv2 hash | ||||
| CVE-2025-2777 | 1 Sysaid | 1 Sysaid | 2025-06-27 | 9.3 Critical | 
| SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives. | ||||
| CVE-2015-3000 | 1 Sysaid | 1 Sysaid | 2025-04-12 | N/A | 
| SysAid Help Desk before 15.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of nested entity references in an XML document to (1) /agententry, (2) /rdsmonitoringresponse, or (3) /androidactions, aka an XML Entity Expansion (XEE) attack. | ||||
| CVE-2015-2996 | 1 Sysaid | 1 Sysaid | 2025-04-12 | N/A | 
| Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the fileName parameter to getGfiUpgradeFile or (2) cause a denial of service (CPU and memory consumption) via a .. (dot dot) in the fileName parameter to calculateRdsFileChecksum. | ||||
| CVE-2015-2997 | 1 Sysaid | 1 Sysaid | 2025-04-12 | N/A | 
| SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getAgentLogFile, as demonstrated by a large directory traversal sequence, which reveals the installation path in an error message. | ||||
| CVE-2015-2995 | 1 Sysaid | 1 Sysaid | 2025-04-12 | N/A | 
| The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote attackers to upload and execute arbitrary files via a NULL byte after the extension, as demonstrated by a .war%00 file. | ||||
| CVE-2014-9436 | 1 Sysaid | 1 Sysaid | 2025-04-12 | N/A | 
| Absolute path traversal vulnerability in SysAid On-Premise before 14.4.2 allows remote attackers to read arbitrary files via a \\\\ (four backslashes) in the fileName parameter to getRdsLogFile. | ||||
| CVE-2015-2994 | 1 Sysaid | 1 Sysaid | 2025-04-12 | N/A | 
| Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators to execute arbitrary code by uploading a file with a .jsp extension, then accessing it via a direct request to the file in icons/user_photo/. | ||||
| CVE-2015-2993 | 1 Sysaid | 1 Sysaid | 2025-04-12 | N/A | 
| SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to /createnewaccount or (2) write to arbitrary files via the fileName parameter to /userentry. | ||||
| CVE-2015-2998 | 1 Sysaid | 1 Sysaid | 2025-04-12 | N/A | 
| SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensitive information, as demonstrated by decrypting the database password in WEB-INF/conf/serverConf.xml. | ||||
| CVE-2015-2999 | 1 Sysaid | 1 Sysaid | 2025-04-12 | N/A | 
| Multiple SQL injection vulnerabilities in SysAid Help Desk before 15.2 allow remote administrators to execute arbitrary SQL commands via the (1) groupFilter parameter in an AssetDetails report to /genericreport, customSQL parameter in a (2) TopAdministratorsByAverageTimer report or an (3) ActiveRequests report to /genericreport, (4) dir parameter to HelpDesk.jsp, or (5) grantSQL parameter to RFCGantt.jsp. | ||||
| CVE-2015-3001 | 1 Sysaid | 1 Sysaid | 2025-04-12 | N/A | 
| SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password. | ||||
| CVE-2024-36394 | 1 Sysaid | 1 Sysaid | 2024-11-21 | 9.1 Critical | 
| SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | ||||
| CVE-2024-36393 | 1 Sysaid | 1 Sysaid | 2024-11-21 | 9.9 Critical | 
| SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | ||||
| CVE-2023-47247 | 1 Sysaid | 1 Sysaid | 2024-11-21 | 4.3 Medium | 
| In SysAid On-Premise before 23.3.34, there is an edge case in which an end user is able to delete a Knowledge Base article, aka bug 15102. | ||||
| CVE-2023-33706 | 1 Sysaid | 1 Sysaid | 2024-11-21 | 6.5 Medium | 
| SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modified srID parameter to ShowMessage.jsp. | ||||
| CVE-2022-23166 | 1 Sysaid | 1 Sysaid | 2024-11-21 | 6.1 Medium | 
| Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/tinymce/examples/index.html" path. in the "Insert/Edit Embedded Media" window Choose Type : iFrame and File/URL : [here is the LFI] Solution: Update to 22.2.20 cloud version, or to 22.1.64 on premise version. | ||||
 ReportizFlow
ReportizFlow