PT-2025-33880 · Unknown · Solidinvoice
Gabrielmoura
·
Published
2025-08-19
·
Updated
2025-08-20
·
CVE-2025-9169
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
SolidInvoice versions prior to 2.4.1
Description:
A cross-site scripting issue exists in SolidInvoice. The vulnerability affects an unknown function within the
/quotes file of the Quote Module. Manipulation of the Name argument can lead to cross-site scripting attacks. Remote exploitation is possible, and the exploit has been publicly disclosed. The vendor was notified but did not respond.Recommendations:
SolidInvoice versions prior to 2.4.1 are affected and should be updated.
Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Solidinvoice