CVE-2025-2711
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 24, 2025
Updated: Mar 27, 2025
CWE ID 476
Summary
CVE-2025-2711 is a newly disclosed vulnerability affecting the Yonyou UFIDA ERP-NC 5.0 system. This issue, classified as problematic, impacts an unknown function in the file /help/systop.jsp. A cross-site scripting (XSS) attack can be executed by manipulating the langcode argument. The exploitation of this vulnerability can be done remotely, posing a significant risk. The public disclosure of the exploit increases the likelihood of its use in malicious activities. Despite early notification, the vendor has not responded to the disclosure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- XMLSoft Libxml 2
- libxml2
Affected Vendors
- GNOME Project
- Xmlsoft