CVE-2025-66370

Published
View on NVD ↗
CVSS v3
5
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the server's filesystem.

Web-based ERP system for the German market
GitHubGitHub
117