Metrics
Affected Vendors & Products
Thu, 21 Aug 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Solidinvoice
Solidinvoice solidinvoice |
|
| CPEs | cpe:2.3:a:solidinvoice:solidinvoice:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Solidinvoice
Solidinvoice solidinvoice |
Wed, 20 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 Aug 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file /clients of the component Clients Module. Performing manipulation of the argument Name results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | SolidInvoice Clients clients cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-08-19T22:32:05.818Z
Updated: 2025-08-20T15:16:20.030Z
Reserved: 2025-08-19T13:37:07.795Z
Link: CVE-2025-9171
Updated: 2025-08-20T13:59:33.639Z
Status : Analyzed
Published: 2025-08-19T23:15:27.647
Modified: 2025-08-21T18:27:55.687
Link: CVE-2025-9171
No data.