PT-2025-48312 · Kivitendo · Kivitendo
Published
2025-11-28
·
Updated
2025-12-26
·
CVE-2025-66370
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kivitendo versions prior to 3.9.2
Description
Kivitendo is susceptible to an XML External Entity (XXE) injection. An attacker can exploit this by uploading an electronic invoice in the ZUGFeRD format, potentially allowing them to read and exfiltrate files from the server's filesystem. XXE injection occurs when an application parses XML input that contains a reference to an external entity. This can allow an attacker to access sensitive information or execute arbitrary code on the server.
Recommendations
Update Kivitendo to version 3.9.2 or later.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kivitendo