Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-55580 — Proof-of-concept for a stored cross-site scripting (XSS) vulnerability in SolidInvoice client module, enabling session hijacking and arbitrary JavaScript execution for authenticated users. | Kitploit
Tools/GitHubGitHub/ddobrev25/cve-2025-55580
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & Education
GitHubddobrev25/cve-2025-55580

CVE-2025-55580

Proof-of-concept for a stored cross-site scripting (XSS) vulnerability in SolidInvoice client module, enabling session hijacking and arbitrary JavaScript execution for authenticated users.

View Repository
11 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-55580 - SolidInvoice Stored Cross-Site Scripting (XSS) in Clients

Summary

SolidInvoice is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Client Module. An authenticated attacker can inject arbitrary JavaScript into the application, which will then execute in users' browsers.

Affected Versions

  • Vulnerable: 2.3.7
  • Fixed: 2.3.8

Impact

Exploitation allows a malicious user to store arbitrary JavaScript in the application, which will execute in the context of other authenticated users who view the Clients page. If the application is deployed in a multi-user environment - for example, with multiple admins, this could lead to:

  • Session hijacking
  • Credential or token theft
  • Phishing or social engineering attacks
  • Arbitrary actions performed on behalf of another user

Proof-of-Concept

  1. Navigate to Clients > Add Client.
  2. Enter a payload in the Name field with the following format:
    <script>prompt(document.cookie)</script>
    
  3. Fill in all required fields and save the client.
  4. Visit Clients > List Clients to trigger the script.

Remediation

Update SolidInvoice to version 2.3.8 or later.

References

Product: https://solidinvoice.co/

Download Tool