CVE-2025-9168: SolidInvoice Invoice Creation invoice cross site scripting
A vulnerability was found in SolidInvoice up to 2.4.0. This issue affects some unknown processing of the file /invoice of the component Invoice Creation Module. The manipulation of the argument Client Name results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9168?
CVE-2025-9168 is considered a high severity vulnerability due to its potential for cross site scripting attacks.
How do I fix CVE-2025-9168?
To fix CVE-2025-9168, upgrade SolidInvoice to the latest version beyond 2.4.0 that addresses this vulnerability.
What components are affected by CVE-2025-9168?
CVE-2025-9168 affects the Invoice Creation Module in SolidInvoice versions up to 2.4.0.
Can CVE-2025-9168 be exploited remotely?
Yes, CVE-2025-9168 can be exploited remotely by manipulating the Client Name argument.
What type of attack is associated with CVE-2025-9168?
CVE-2025-9168 is associated with cross site scripting (XSS) attacks.