PT-2026-22315 · Xerox · Xerox Freeflow Core

CVE-2026-2252

·

Publicado

2026-02-27

·

Atualizado

2026-03-04

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xerox FreeFlow Core versions up to and including 8.0.7
Description An XML External Entity (XXE) issue allows a malicious user to perform Server-Side Request Forgery (SSRF) by submitting specially crafted XML input that includes malicious external entity references. This allows an attacker to potentially make requests to internal or external resources on behalf of the server.
Recommendations Upgrade to Xerox FreeFlow Core version 8.1.0.

Correção

XXE

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2252

Produtos afetados

Xerox Freeflow Core