Vulnerabilities in Xerox Print Orchestration Product Allow Remote Code Execution

Post Reply
Shane1145
Posts: 1624
Joined: Wed Sep 25, 2024 2:31 pm

Vulnerabilities in Xerox Print Orchestration Product Allow Remote Code Execution

Post by Shane1145 »

Two serious vulnerabilities were patched recently by Xerox in its FreeFlow Core print orchestration platform.

According to pentesting company Horizon3, whose researchers discovered the flaws, FreeFlow Core is affected by an XXE injection flaw (CVE-2025-8355) and a path traversal issue (CVE-2025-8356).

The researchers discovered that the vulnerabilities could allow an unauthenticated, remote attacker to execute arbitrary code on affected FreeFlow Core instances.


https://www.securityweek.com/vulnerabil ... execution/
Post Reply