PT-2026-22315 · Xerox · Xerox Freeflow Core
CVE-2026-2252
·
Publicado
2026-02-27
·
Atualizado
2026-03-04
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Xerox FreeFlow Core versions up to and including 8.0.7
Description
An XML External Entity (XXE) issue allows a malicious user to perform Server-Side Request Forgery (SSRF) by submitting specially crafted XML input that includes malicious external entity references. This allows an attacker to potentially make requests to internal or external resources on behalf of the server.
Recommendations
Upgrade to Xerox FreeFlow Core version 8.1.0.
Correção
XXE
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Xerox Freeflow Core