Xerox FreeFlow Core
cpe:2.3:a:xerox:freeflow_core:*:*:*:*:*:*:*
- <= 8.0.7
A vulnerability allowing XML External Entity (XXE) processing has been identified in Xerox FreeFlow Core versions prior to 8.1.0. This vulnerability enables malicious users to perform Server-Side Request Forgery (SSRF) by sending crafted XML input that includes harmful external entity references.
Exploitation of this vulnerability allows for Server-Side Request Forgery, where an attacker can make the server send requests on its behalf, potentially leading to unauthorized access or manipulation of data.
Users are advised to upgrade to Xerox FreeFlow Core version 8.1.0, available through the Xerox Support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.