CVE-2025-67344: XSS
Published Dec 12, 2025
·Updated
jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the /msg/add endpoint.
Affected Software
2 affected components
jshERP jshERP<=3.5
jishenghua jshERP<=3.5
Event History
Dec 12, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-67344?
CVE-2025-67344 has a moderate severity rating due to its potential for stored Cross Site Scripting (XSS) attacks.
2
How do I fix CVE-2025-67344?
To fix CVE-2025-67344, upgrade jshERP to version 3.6 or later where the vulnerability is patched.
3
What products are affected by CVE-2025-67344?
CVE-2025-67344 affects jshERP versions 3.5 and earlier.
4
What is a stored Cross Site Scripting vulnerability related to CVE-2025-67344?
A stored Cross Site Scripting vulnerability like CVE-2025-67344 allows an attacker to inject malicious scripts that can be executed by users visiting the affected endpoint.
5
Is there a public report for CVE-2025-67344?
Yes, public reports and discussions about CVE-2025-67344 can be found in the jshERP GitHub issues section.