kivitendo/kivitendo-erp

kivitendo/kivitendo-erp

Releases126
Frequency1 month 2 weeks
Last Release
Stars117
Web-based ERP system for the German market

CVE History

CVEPublishedCVSS v3CVSS v2
5 MEDIUM

Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the server's filesystem.