CVE-2025-8355

Publication date

2025-08-08 15:31:44

Family

Xerox

State

PUBLISHED

Description

In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).