3.5 CVE-2025-9168

Exploit
 

A vulnerability was found in SolidInvoice up to 2.4.0. This issue affects some unknown processing of the file /invoice of the component Invoice Creation Module. The manipulation of the argument Client Name results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
https://nvd.nist.gov/vuln/detail/CVE-2025-9168

Categories

CWE-79

References

134c704f-9b21-4f2e-91b3-4a467353bcc0 Exploit

cna@vuldb.com Exploit


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:solidinvoice:solidinvoice:*:*:*:*:*:*:*:* <= 2.4.0


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url

Other Nist (github, ...)

Url
https://github.com/Gabrielmouraofc/PoC_Vuldb/blob/main/%F0%9F%93%84POC%20Stor...
https://github.com/Gabrielmouraofc/PoC_Vuldb/blob/main/%F0%9F%93%84POC%20Stor...
https://github.com/Gabrielmouraofc/PoC_Vuldb/blob/main/%F0%9F%93%84POC%20Stor...


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry