PT-2025-33883 · Unknown · Solidinvoice
Gabrielmoura
·
Published
2025-08-19
·
Updated
2025-11-11
·
CVE-2025-9171
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
SolidInvoice versions prior to 2.4.1
Description:
A security flaw has been discovered in SolidInvoice. The impacted element is an unknown function within the
/clients file of the Clients Module. Manipulation of the Name argument results in cross-site scripting. The attack can be carried out remotely, and the exploit has been released publicly. The vendor was contacted regarding this disclosure but did not respond.Recommendations:
SolidInvoice versions prior to 2.4.1: Update to version 2.4.1 or later to address the issue. As a temporary workaround, consider restricting or disabling access to the
/clients file or the Clients Module until a patch can be applied.Exploit
Fix
DoS
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Solidinvoice