In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).
                
            References
                    Configurations
                    History
                    14 Aug 2025, 16:19
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:xerox:freeflow_core:8.0.4:*:*:*:*:*:*:* | |
| References | () https://securitydocs.business.xerox.com/wp-content/uploads/2025/08/Xerox-Security-Bulletin-025-013-for-Freeflow-Core-8.0.5.pdf - Vendor Advisory | |
| Summary | 
 | |
| First Time | Xerox freeflow Core Xerox | 
08 Aug 2025, 16:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-08-08 16:15
Updated : 2025-08-14 16:19
NVD link : CVE-2025-8355
Mitre link : CVE-2025-8355
CVE.ORG link : CVE-2025-8355
JSON object : View
Products Affected
                xerox
- freeflow_core
CWE
                
                    
                        
                        CWE-611
                        
            Improper Restriction of XML External Entity Reference
