Skip to content
Saturday, December 6, 2025
High Published: Aug 08, 2025 Modified: Aug 14, 2025

CVE-2025-8355

7.5 CVSS Score
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Share:

Description

In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).

CVSS Vector Details

Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability None

Affected Software Configurations

  • a xerox freeflow_core 8.0.4 * * * * * * *

Weaknesses (CWE)

  • CWE-611