3.5 CVE-2025-9167

Exploit
 

A vulnerability has been found in SolidInvoice up to 2.4.0. This vulnerability affects unknown code of the file /invoice/recurring of the component Recurring Invoice Module. The manipulation of the argument client name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
https://nvd.nist.gov/vuln/detail/CVE-2025-9167

Categories

CWE-79

References

134c704f-9b21-4f2e-91b3-4a467353bcc0 Exploit

cna@vuldb.com Exploit


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:solidinvoice:solidinvoice:*:*:*:*:*:*:*:* <= 2.4.0


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url

Other Nist (github, ...)

Url
https://github.com/Gabrielmouraofc/PoC_Vuldb/blob/main/%F0%9F%95%B5%EF%B8%8F%...
https://github.com/Gabrielmouraofc/PoC_Vuldb/blob/main/%F0%9F%95%B5%EF%B8%8F%...
https://github.com/Gabrielmouraofc/PoC_Vuldb/blob/main/%F0%9F%95%B5%EF%B8%8F%...


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry