3.5 CVE-2025-9171

Exploit
 

A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file /clients of the component Clients Module. Performing manipulation of the argument Name results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
https://nvd.nist.gov/vuln/detail/CVE-2025-9171

Categories

CWE-79

References

134c704f-9b21-4f2e-91b3-4a467353bcc0 Exploit

cna@vuldb.com Exploit


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:solidinvoice:solidinvoice:*:*:*:*:*:*:*:* <= 2.4.0


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url

Other Nist (github, ...)

Url
https://github.com/Gabrielmouraofc/PoC_Vuldb/blob/main/%F0%9F%95%B5%EF%B8%8F%...
https://github.com/Gabrielmouraofc/PoC_Vuldb/blob/main/%F0%9F%95%B5%EF%B8%8F%...
https://github.com/Gabrielmouraofc/PoC_Vuldb/blob/main/%F0%9F%95%B5%EF%B8%8F%...


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry