Xerox FreeFlow Core
cpe:2.3:a:xerox:freeflow_core:*:*:*:*:*:*:*
- 8.0.4
A vulnerability in Xerox FreeFlow Core version 8.0.4 allows for Server-Side Request Forgery (SSRF) through improper handling of XML input, which enables the injection of external entities. An attacker can create malicious XML that references internal URLs, leading to unauthorized requests being made from the server.
Exploitation of this vulnerability allows for Server-Side Request Forgery, where an attacker can make the server send requests to internal resources, potentially leading to further exploitation or information disclosure.
Users are advised to upgrade to Xerox FreeFlow Core version 8.0.5, available through the Xerox support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.