An XML external entities (XXE) injection vulnerability in the /init API endpoint in Exagid EX10 7.0.1p02 allows an authenticated, unprivileged attacker to achieve information disclosure and privilege escalation via a crafted ISys XML message.
https://www.exagrid.com/exagrid-products/exagrid-product-line/
https://github.com/atredispartners/advisories/blob/master/2025/ATREDIS-2025-0004.md