CVE-2025-9169: SolidInvoice Quote quotes cross site scripting
A vulnerability was determined in SolidInvoice up to 2.4.0. Impacted is an unknown function of the file /quotes of the component Quote Module. This manipulation of the argument Name causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9169?
The severity of CVE-2025-9169 is classified as high due to its potential for remote exploitation.
How do I fix CVE-2025-9169?
To fix CVE-2025-9169, update SolidInvoice to version 2.4.1 or later, which addresses this vulnerability.
What is the impact of CVE-2025-9169?
CVE-2025-9169 allows attackers to perform cross-site scripting (XSS) via the Quote Module in impacted versions of SolidInvoice.
Are there any affected versions for CVE-2025-9169?
Yes, CVE-2025-9169 affects all versions of SolidInvoice up to and including 2.4.0.
Is remote exploitation possible with CVE-2025-9169?
Yes, remote exploitation is possible with CVE-2025-9169, making it critical to mitigate the vulnerability.