Record summary

CVE-2025-2710 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This issue affects some unknown processing of the file /menu.jsp. The manipulation of the argument flag leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 25, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List5.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMYonyou UFIDA ERP-NC V5.0 - Cross-Site ScriptingCVSS 6.1

Yonyou UFIDA ERP-NC V5.0 is vulnerable to reflected cross-site scripting (XSS) via the flag parameter in menu.jsp. Unsanitized user input is reflected in the response, allowing arbitrary JavaScript execution.

Impact

Successful exploitation of this XSS vulnerability allows attackers to execute arbitrary JavaScript code in victims' browsers, potentially leading to session hijacking, credential theft, or other malicious activities in the ERP system.

Remediation

Update Yonyou UFIDA ERP-NC to the latest version. Implement proper input validation and output encoding for all user-supplied data, especially the flag parameter in menu.jsp.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2025xsserp-ncufidayonyouvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:yonyou:ufida_erp-nc:5.0:*:*:*:*:*:*:*
Shodan: title:"用友"
FOFA: icon_hash="1085941792"

Source: ProjectDiscovery

References

5