ZeroHour

CVE-2025-67341

PoC
CVSS 3.1
4.6 medium
EPSS
<1%p7
Published
()
Modified
Description

jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to upload PDF files containing XSS payloads. Additionally, these PDF files can be accessed via static URLs, making them accessible to all users.

Vendors
jishenghua
Products
jsherp
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.