PT-2025-48312 · Kivitendo · Kivitendo

CVE-2025-66370

·

Publicado

2025-11-28

·

Atualizado

2025-12-26

CVSS v3.1

5.0

Média

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kivitendo versions prior to 3.9.2
Description Kivitendo is susceptible to an XML External Entity (XXE) injection. An attacker can exploit this by uploading an electronic invoice in the ZUGFeRD format, potentially allowing them to read and exfiltrate files from the server's filesystem. XXE injection occurs when an application parses XML input that contains a reference to an external entity. This can allow an attacker to access sensitive information or execute arbitrary code on the server.
Recommendations Update Kivitendo to version 3.9.2 or later.

Exploit

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-66370

Produtos afetados

Kivitendo