CVE-2025-3706
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2025-3706 is a Reflected Cross-site Scripting (XSS) vulnerability affecting the eHRMS system from 104 Corporation. This issue enables unauthenticated attackers to inject malicious JavaScript codes into a user's web browser via phishing attacks, potentially leading to data theft or unauthorized access. By exploiting this flaw, an attacker can execute arbitrary scripts on unsuspecting victims, putting their sensitive information at risk. Users are advised to exercise caution when clicking on suspicious links and update their eHRMS software as soon as a patch is released to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.