CVE-2025-66370
28.11.2025, 04:16
Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the server's filesystem.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
References