CVE-2025-55580: XSS
SolidInvoice version 2.3.7 is vulnerable to a stored cross-site scripting (XSS) issue in the Clients module. An authenticated attacker can inject JavaScript that executes in other users' browsers when the Clients page is viewed. The vulnerability is fixed in version 2.3.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55580?
CVE-2025-55580 is classified as a medium severity vulnerability due to the potential impact of Cross Site Scripting (XSS) on user clients.
How do I fix CVE-2025-55580?
To fix CVE-2025-55580, upgrade SolidInvoice to version 2.3.9 or later, which addresses the XSS vulnerability.
What versions of SolidInvoice are affected by CVE-2025-55580?
CVE-2025-55580 affects SolidInvoice versions 2.3.7 and 2.3.8.
What type of vulnerability is CVE-2025-55580?
CVE-2025-55580 is a Cross Site Scripting (XSS) vulnerability found in SolidInvoice.
What are the potential risks of CVE-2025-55580?
The risks of CVE-2025-55580 include unauthorized access to user information and potential exploitation through malicious scripts.