SysAid disclosed CVE-2023-47246, a critical path traversal vulnerability in their on-premise server software that allows unauthenticated attackers to upload WAR file webshells and achieve remote code execution. The flaw exists in the doPost method of the UserEntry Java class, where the accountID parameter is used unsanitized to construct file write paths. Huntress recreated a fully weaponized proof of concept by analyzing the patch diff between versions 23.3.35 and 23.3.36. Active exploitation has been attributed to TA505 (Cl0p ransomware gang), the same group behind the MOVEit Transfer attacks. Post-exploitation activity includes GraceWire malware deployment, Sophos AV evasion, and log-cleaning routines targeting SysAid and Tomcat logs. Shodan reveals up to 900 publicly accessible SysAid instances. Patching to version 23.3.36 is strongly recommended immediately.

7m read timeFrom huntress.com
Post cover image
Table of contents
The VulnerabilityThe ImpactAttack SurfaceExploitation Proof of ConceptIndicators of Compromise