PT-2025-1591 · Uyumsoft · Uyumsoft Erp

Havelsan Inc

·

Published

2025-01-23

·

Updated

2025-01-23

·

CVE-2024-10539

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Uyumsoft ERP versions prior to Erp4.2109.166p45
Description The issue is related to Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS). This allows for XSS using invalid characters and Reflected XSS.
Recommendations For versions prior to Erp4.2109.166p45, update to a version Erp4.2109.166p45 or later to resolve the issue. As a temporary workaround, consider restricting user input to prevent the use of invalid characters in web page generation until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-10539

Affected Products

Uyumsoft Erp