PT-2025-33880 · Unknown · Solidinvoice
Gabrielmoura
·
Publicado
2025-08-19
·
Atualizado
2025-08-20
·
CVE-2025-9169
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
SolidInvoice versions prior to 2.4.1
Description:
A cross-site scripting issue exists in SolidInvoice. The vulnerability affects an unknown function within the
/quotes file of the Quote Module. Manipulation of the Name argument can lead to cross-site scripting attacks. Remote exploitation is possible, and the exploit has been publicly disclosed. The vendor was notified but did not respond.Recommendations:
SolidInvoice versions prior to 2.4.1 are affected and should be updated.
Exploit
Correção
XSS
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Solidinvoice