CVE-2025-8355
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).
Affected (1)
Products: Xerox: Freeflow Core
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0.4 |
References (1)
Source: 10b61619-3869-496c-8a1e-f291b0e71e3f
Vendor Advisory
Timeline
No history available yet.