CVE 7.5 HIGH

XXE leading to SSRF_CVE-2025-8355

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).

Basic Information

ID CVE-2025-8355
Source Xerox
Published Aug 8, 2025 at 15:31
Modified Aug 8, 2025 at 16:02

Affected Product

Vendor Xerox
Product FreeFlow Core
Affected Versions Xerox FreeFlow Core 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.