CVE-2025-55579
MEDIUMSolidInvoice 2.3.7 - Stored Cross-Site Scripting in Tax Rates Functionality
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-55579. PoCs published by ddobrev25.
AI-analyzed exploit summary This repository contains a writeup for CVE-2025-55579, detailing a Stored Cross-Site Scripting (XSS) vulnerability in SolidInvoice's Tax Rates feature. The PoC describes how an authenticated attacker can inject arbitrary JavaScript, which executes when other users view the Tax Rates page.
Description
SolidInvoice version 2.3.7 is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Tax Rates functionality. The vulnerability is fixed in version 2.3.8.
Exploits (1)
This repository contains a writeup for CVE-2025-55579, detailing a Stored Cross-Site Scripting (XSS) vulnerability in SolidInvoice's Tax Rates feature. The PoC describes how an authenticated attacker can inject arbitrary JavaScript, which executes when other users view the Tax Rates page.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N