CVE-2025-2778

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-2778 is a command injection vulnerability that affects SysAid On-Premise IT Support Software. It exists in version 23.3.40 and prior. Successful exploitation could allow a remote attacker to execute arbitrary commands on the affected system. The vulnerability allows attackers to execute arbitrary commands on the host operating system. This can be combined with XXE vulnerabilities to achieve remote code execution. SysAid has released security updates to address this vulnerability.

Description
-

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.