CVE-2025-9170: SolidInvoice Tax Rates rates cross site scripting
A vulnerability was identified in SolidInvoice up to 2.4.0. The affected element is an unknown function of the file /tax/rates of the component Tax Rates Module. Such manipulation of the argument Name leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9170?
The severity of CVE-2025-9170 is considered high due to its potential for remote exploitation through cross site scripting.
How do I fix CVE-2025-9170?
To fix CVE-2025-9170, ensure that you upgrade SolidInvoice to version 2.4.1 or later where the vulnerability is addressed.
What type of attack is associated with CVE-2025-9170?
CVE-2025-9170 is associated with cross site scripting attacks that can be executed remotely.
Which versions of SolidInvoice are affected by CVE-2025-9170?
SolidInvoice versions up to and including 2.4.0 are affected by CVE-2025-9170.
What components are impacted by CVE-2025-9170?
The vulnerability in CVE-2025-9170 impacts the Tax Rates Module located in the /tax/rates file.