Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23998 | In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF). |
Thu, 14 Aug 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:xerox:freeflow_core:8.0.4:*:*:*:*:*:*:* |
Tue, 12 Aug 2025 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xerox
Xerox freeflow Core |
|
| Vendors & Products |
Xerox
Xerox freeflow Core |
Fri, 08 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 Aug 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF). | |
| Title | XXE leading to SSRF | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Xerox
Published:
Updated: 2025-08-08T16:02:42.866Z
Reserved: 2025-07-30T13:54:04.373Z
Link: CVE-2025-8355
Updated: 2025-08-08T16:02:36.229Z
Status : Analyzed
Published: 2025-08-08T16:15:27.917
Modified: 2025-08-14T16:19:37.380
Link: CVE-2025-8355
No data.
OpenCVE Enrichment
Updated: 2025-08-12T07:48:04Z
EUVD