PT-2025-24681 · Keyoti · Searchunit

Published

2025-06-10

·

Updated

2025-06-10

·

CVE-2025-44044

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Keyoti SearchUnit versions prior to 9.0.0
Description The issue allows an attacker to exfiltrate files from the underlying operating system by forcing a vulnerable host into parsing maliciously crafted XML and/or DTD files, exploiting an XML External Entity (XXE) vulnerability.
Recommendations For versions prior to 9.0.0, update to version 9.0.0 or later to resolve the issue. As a temporary workaround, consider restricting the parsing of external XML and DTD files to minimize the risk of exploitation. Avoid using vulnerable SearchUnit configurations until the issue is resolved.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2025-44044

Affected Products

Searchunit