Vulnerability Description
jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to upload PDF files containing XSS payloads. Additionally, these PDF files can be accessed via static URLs, making them accessible to all users.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jishenghua | Jsherp | <= 3.5 |
Related Weaknesses (CWE)
References
- https://github.com/jishenghua/jshERP/issues/139ExploitIssue TrackingVendor Advisory
FAQ
What is CVE-2025-67341?
CVE-2025-67341 is a vulnerability with a CVSS score of 4.6 (MEDIUM). jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to upload PDF files containing XSS payloads. Additionally, these PDF files can be access...
How severe is CVE-2025-67341?
CVE-2025-67341 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-67341?
Check the references section above for vendor advisories and patch information. Affected products include: Jishenghua Jsherp.