CVE 5 MEDIUM

CVE-2025-66370_CVE-2025-66370

5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Description

Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the server's filesystem.

Basic Information

ID CVE-2025-66370
Source mitre
Published Nov 28, 2025 at 00:00
Modified Nov 28, 2025 at 03:33

Affected Product

Vendor kivitendo
Product kivitendo
Affected Versions kivitendo kivitendo 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.