CVE-2025-12872: aEnrich|eHRD - Stored Cross-Site Scripting
The a+HRD and a+HCM developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to upload files containing malicious JavaScript code, which will execute on the client side when a user is tricked into visiting a specific URL.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12872?
CVE-2025-12872 has a high severity rating due to its potential for exploitation via Stored Cross-Site Scripting.
How do I fix CVE-2025-12872?
To fix CVE-2025-12872, validate and sanitize all user inputs to prevent the execution of malicious scripts.
Who is affected by CVE-2025-12872?
CVE-2025-12872 affects the a+HRD and a+HCM products developed by aEnrich.
Can CVE-2025-12872 lead to data theft?
Yes, if exploited, CVE-2025-12872 can allow attackers to execute malicious scripts that may lead to data theft.
Is authentication required to exploit CVE-2025-12872?
Yes, CVE-2025-12872 requires authentication as it allows authenticated users to upload malicious files.