In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).
References
Configurations
History
14 Aug 2025, 16:19
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
First Time |
Xerox freeflow Core
Xerox |
|
CPE | cpe:2.3:a:xerox:freeflow_core:8.0.4:*:*:*:*:*:*:* | |
References | () https://securitydocs.business.xerox.com/wp-content/uploads/2025/08/Xerox-Security-Bulletin-025-013-for-Freeflow-Core-8.0.5.pdf - Vendor Advisory |
08 Aug 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-08 16:15
Updated : 2025-08-14 16:19
NVD link : CVE-2025-8355
Mitre link : CVE-2025-8355
CVE.ORG link : CVE-2025-8355
JSON object : View
Products Affected
xerox
- freeflow_core
CWE
CWE-611
Improper Restriction of XML External Entity Reference