CVE-2025-2712

CVSS 2.0 Score 5 of 10 (medium)

Details

Published Mar 24, 2025
Updated: Mar 27, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-2712 is a newly disclosed vulnerability affecting Yonyou UFIDA ERP-NC 5.0. This issue lies in an unidentified functionality of the file /help/top.jsp, where manipulation of the langcode argument results in cross-site scripting (XSS). The attack can be executed remotely, and the exploit has become publicly available. Despite early contact, the vendor has yet to respond to the disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share