Vulnerability Description
The a+HRD and a+HCM developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to upload files containing malicious JavaScript code, which will execute on the client side when a user is tricked into visiting a specific URL.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://www.twcert.org.tw/en/cp-139-10487-12a32-2.html
- https://www.twcert.org.tw/tw/cp-132-10486-a3459-1.html
FAQ
What is CVE-2025-12872?
CVE-2025-12872 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The a+HRD and a+HCM developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to upload files containing malicious JavaScript code, which will execu...
How severe is CVE-2025-12872?
CVE-2025-12872 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-12872?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.