← Back to browse · API

CVE-2025-8356

Severity
CRITICAL
CVSS
9.8
EPSS
0.14774
Risk score
44.37
CISA KEV
No
PoC
No
Published
2025-08-08
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-23999, GHSA-6RPM-HQP2-MF48
Products
XEROX:FreeFlow Core 0 <8.0.5
Sources
euvd EUVD-2025-23999

Description

In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run arbitrary commands on the system.

References