CVE-2025-2712
CVSS 2.0 Score 5 of 10 (medium)
Details
Published Mar 24, 2025
Updated: Mar 27, 2025
CWE ID 94
CWE ID 79
Summary
CVE-2025-2712 is a newly disclosed vulnerability affecting Yonyou UFIDA ERP-NC 5.0. This issue lies in an unidentified functionality of the file /help/top.jsp, where manipulation of the langcode argument results in cross-site scripting (XSS). The attack can be executed remotely, and the exploit has become publicly available. Despite early contact, the vendor has yet to respond to the disclosure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Yonyou Network Technology Co., Ltd