Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-8355


In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).


Published

2025-08-08T16:15:27.917

Last Modified

2025-08-14T16:19:37.380

Status

Analyzed

Source

10b61619-3869-496c-8a1e-f291b0e71e3f

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application xerox freeflow_core 8.0.4 Yes

References