CVE-2025-8355
HIGHXerox FreeFlow Core 8.0.4 - Server-Side Request Forgery via XML External Entity Injection
Title source: llmDescription
In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).
References (1)
Core 1
Core References
Scores
CVSS v3
7.5
EPSS
0.0693
EPSS Percentile
93.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-611
Status
published
Products (1)
xerox/freeflow_core
8.0.4
Published
Aug 08, 2025
Tracked Since
Feb 18, 2026