Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the server's filesystem.
Publication date: Fri, 28 Nov 2025 00:00:00 +0000
Cyber News related to CVE-2025-66370
CVE-2025-66370 - Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the server's filesystem. ...
16 hours ago