PT-2025-50955 · Jsherp · Jsherp

Arron-Bit

·

Published

2025-12-12

·

Updated

2025-12-19

·

CVE-2025-67344

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions jshERP versions prior to 3.5
Description The software is susceptible to a stored Cross Site Scripting (XSS) issue. The vulnerability exists through the /msg/add API endpoint. An attacker could potentially inject malicious scripts that are then stored and executed when other users access the affected functionality. The vulnerable parameter is not specified.
Recommendations Update to a version newer than 3.5. As a temporary workaround, consider restricting access to the /msg/add endpoint until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-67344

Affected Products

Jsherp