CVE-2025-2712: Yonyou UFIDA ERP-NC top.jsp cross site scripting
A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /help/top.jsp. The manipulation of the argument langcode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2712?
CVE-2025-2712 has been declared as problematic due to its potential for exploitation through cross-site scripting.
How does CVE-2025-2712 affect Yonyou UFIDA ERP-NC?
CVE-2025-2712 affects an unknown functionality of the file /help/top.jsp in Yonyou UFIDA ERP-NC 5.0.
What is the nature of the vulnerability in CVE-2025-2712?
CVE-2025-2712 is a cross-site scripting vulnerability that can be exploited by manipulating the argument langcode.
Can CVE-2025-2712 be exploited remotely?
Yes, CVE-2025-2712 can be exploited remotely, allowing attackers to execute malicious scripts.
How can I mitigate CVE-2025-2712?
To mitigate CVE-2025-2712, ensure that input validation and output encoding are applied to the langcode parameter in your application.