7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).
Basic Information
ID
CVE-2025-8355
Source
Xerox
Published
Aug 8, 2025 at 15:31
Modified
Aug 8, 2025 at 16:02
Affected Product
Vendor
Xerox
Product
FreeFlow Core
Affected Versions
Xerox FreeFlow Core 0