Skip to content
Noroxi

SysAid records

40 published records for vendor sysaid.

All records

40 records
  • In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat we

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    sysaid · sysaidNov 10, 2023

  • SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection

    CriticalCVSS 9.8KEVWeaponizedEPSS 64%

    sysaid · sysaidMay 7, 2025

  • CVE-2025-2775
    73This week

    SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection

    HighCVSS 7.5KEVWeaponizedEPSS 43%

    sysaid · sysaidMay 7, 2025

  • CVE-2025-2777
    61This week

    SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection

    CriticalCVSS 9.8Proof of conceptEPSS 72%

    sysaid · sysaidMay 7, 2025

  • CVE-2015-2996
    60This week

    Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrary files via a ..

    HighCVSS 8.5WeaponizedEPSS 87%

    sysaid · sysaidJun 8, 2015

  • SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create adminis

    HighCVSS 7.5WeaponizedEPSS 55%

    sysaid · sysaidJun 8, 2015

  • Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators to execute arbitrary

    MediumCVSS 6.5WeaponizedEPSS 50%

    sysaid · sysaidJun 8, 2015

  • SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack.

    CriticalCVSS 9.8No exploitEPSS 3%

    sysaid · on-premiseApr 21, 2020

  • Sysaid – Sysaid System Takeover

    CriticalCVSS 9.8No exploitEPSS 1%

    sysaid · sysaidMay 12, 2022

  • Sysaid – Sysaid Local File Inclusion (LFI)

    CriticalCVSS 9.8No exploitEPSS 1%

    sysaid · sysaidMay 12, 2022

  • SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    CriticalCVSS 9.8No exploitEPSS 1%

    sysaid · sysaidJun 6, 2024

  • SysAid - Okta SSO integration

    CriticalCVSS 9.8No exploitEPSS 1%

    sysaid · okta ssoJun 24, 2022

  • SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

    CriticalCVSS 9.8No exploitEPSS 0%

    sysaid · sysaidJun 6, 2024

  • CVE-2015-2997
    37Monitor

    SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getA

    MediumCVSS 5.0WeaponizedEPSS 57%

    sysaid · sysaidJun 8, 2015

  • CVE-2015-2995
    37Monitor

    The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote attackers to upload an

    MediumCVSS 6.8WeaponizedEPSS 34%

    sysaid · sysaidJun 8, 2015

  • A SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to execute arbitr

    HighCVSS 8.8No exploitEPSS 2%

    sysaid · sysaidJan 11, 2022

  • An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to upload a

    HighCVSS 8.8No exploitEPSS 2%

    sysaid · sysaidJan 11, 2022

  • SysAid 20.3.64 b14 is affected by Blind and Stacker SQL injection via AssetManagementChart.jsp (GET computerID), AssetManagementChart.jsp (P

    HighCVSS 8.8No exploitEPSS 1%

    sysaid · sysaidJul 22, 2021

  • Sysaid – Pro Plus Edition, SysAid Help Desk Broken Access Control

    HighCVSS 8.8No exploitEPSS 1%

    sysaid · sysaidMay 12, 2022

  • CVE-2015-3000
    33Monitor

    SysAid Help Desk before 15.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of nested

    HighCVSS 7.8Proof of conceptEPSS 8%

    sysaid · sysaidJun 8, 2015

  • CVE-2015-2998
    28Monitor

    SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensitive information, as

    MediumCVSS 5.0WeaponizedEPSS 26%

    sysaid · sysaidJun 8, 2015

  • Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type

    HighCVSS 7.2No exploitEPSS 1%

    sysaid · sysaid on-premisesJul 30, 2023

  • CVE-2015-2999
    27Monitor

    Multiple SQL injection vulnerabilities in SysAid Help Desk before 15.2 allow remote administrators to execute arbitrary SQL commands via the

    MediumCVSS 6.5Proof of conceptEPSS 2%

    sysaid · sysaidJun 8, 2015

  • An unrestricted file copy vulnerability in /UserSelfServiceSettings.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to

    MediumCVSS 6.5No exploitEPSS 1%

    sysaid · sysaidJan 11, 2022

  • SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIfr

    MediumCVSS 6.5No exploitEPSS 1%

    sysaid · sysaidNov 23, 2023