PT-2025-33880 · Unknown · Solidinvoice

·

CVE-2025-9169

·

Published

2025-08-19

·

Updated

2025-08-20

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: SolidInvoice versions prior to 2.4.1
Description: A cross-site scripting issue exists in SolidInvoice. The vulnerability affects an unknown function within the /quotes file of the Quote Module. Manipulation of the Name argument can lead to cross-site scripting attacks. Remote exploitation is possible, and the exploit has been publicly disclosed. The vendor was notified but did not respond.
Recommendations: SolidInvoice versions prior to 2.4.1 are affected and should be updated.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9169

Affected Products

Solidinvoice