PT-2025-50953 · Jsherp · Jsherp

Arron-Bit

·

Published

2025-12-12

·

Updated

2025-12-19

·

CVE-2025-67341

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions jshERP versions 3.5 and earlier
Description The software is susceptible to a stored cross-site scripting (XSS) issue. Attackers can exploit this by uploading PDF files containing malicious XSS payloads. These files are then accessible through static URLs, potentially exposing them to all users.
Recommendations Versions prior to 3.5 should be updated.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-67341

Affected Products

Jsherp