Skip to content
Saturday, December 6, 2025
Critical Published: Aug 08, 2025 Modified: Aug 18, 2025

CVE-2025-8356

9.8 CVSS Score
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Share:

Description

In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run arbitrary commands on the system.

CVSS Vector Details

Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Affected Software Configurations

  • a xerox freeflow_core 8.0.4 * * * * * * *

Weaknesses (CWE)

  • CWE-22