PT-2025-33879 · Unknown · Solidinvoice

Gabrielmoura

·

Published

2025-08-19

·

Updated

2025-08-20

·

CVE-2025-9168

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: SolidInvoice versions prior to 2.4.1
Description: A vulnerability exists in SolidInvoice affecting the Invoice Creation Module. The issue involves an unknown processing of the /invoice file. Manipulation of the Client Name argument results in cross site scripting. The attack can be launched remotely. The exploit has been made public and may be used. The vendor was contacted regarding this disclosure but did not respond.
Recommendations: Update SolidInvoice to version 2.4.1 or later.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-9168

Affected Products

Solidinvoice