Security Advisory
CVE-2025-66370
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the servers filesystem.