CVE-2025-8355

HIGH

Xerox FreeFlow Core 8.0.4 - Server-Side Request Forgery via XML External Entity Injection

Title source: llm
STIX 2.1

Description

In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).

Scores

CVSS v3 7.5
EPSS 0.0693
EPSS Percentile 93.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (1)
xerox/freeflow_core 8.0.4
Published Aug 08, 2025
Tracked Since Feb 18, 2026