SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.
| Software | From | Fixed in |
|---|---|---|
| sysaid / sysaid | - | 23.3.40.x |