Vulnerability Description
Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable SearchUnit host into parsing maliciously crafted XML and/or DTD files can exfiltrate some files from the underlying operating system.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://keyoti.com/products/search/dotNetWeb/HtmlHelp9/?topic=UserGuide/Release%
- https://www.sprocketsecurity.com/blog/cve-alert-cve-2025-44043-cve-2025-44044-th
FAQ
What is CVE-2025-44044?
CVE-2025-44044 is a vulnerability with a CVSS score of 7.5 (HIGH). Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable SearchUnit host into parsing maliciously crafted XML and/or DTD files can exfiltrat...
How severe is CVE-2025-44044?
CVE-2025-44044 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-44044?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.