CVE-2025-9171: SolidInvoice Clients clients cross site scripting
A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file /clients of the component Clients Module. Performing manipulation of the argument Name results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9171?
CVE-2025-9171 has been rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-9171?
To fix CVE-2025-9171, you should update SolidInvoice to version 2.4.1 or later.
What type of vulnerability is CVE-2025-9171?
CVE-2025-9171 is a cross-site scripting (XSS) vulnerability affecting the Clients Module of SolidInvoice.
Which versions of SolidInvoice are affected by CVE-2025-9171?
CVE-2025-9171 affects SolidInvoice versions up to and including 2.4.0.
How can CVE-2025-9171 be exploited?
CVE-2025-9171 can be exploited by manipulating the Name argument in the Clients Module, leading to the execution of malicious scripts.