ZeroHour

CVE-2025-55580

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p18
Published
()
Modified
Description

SolidInvoice version 2.3.7 is vulnerable to a stored cross-site scripting (XSS) issue in the Clients module. An authenticated attacker can inject JavaScript that executes in other users' browsers when the Clients page is viewed. The vulnerability is fixed in version 2.3.8.

Vendors
solidinvoice
Products
solidinvoice
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.