Description
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.
Problem types
CWE-611 Improper Restriction of XML External Entity Reference
Product status
Any version
Credits
Sina Kheirkhah (@SinSinology)
Jake Knott
watchTowr
References
documentation.sysaid.com/docs/24-40-60
labs.watchtowr.com/...wned-your-friendly-rce-support-ticket/