ZeroHour

CVE-2025-66370

CVSS 3.1
5.0 medium
EPSS
<1%p26
Published
()
Modified
Description

Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the server's filesystem.

Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.