Record summary

CVE-2025-2712 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /help/top.jsp. The manipulation of the argument langcode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 31, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 25, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List, VulnCheck5.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMYonyou UFIDA ERP-NC V5.0 - Cross-Site ScriptingCVSS 6.1

Yonyou UFIDA ERP-NC V5.0 is vulnerable to reflected cross-site scripting (XSS) via the langcode parameter in /help/systop.jsp and /help/top.jsp. Unsanitized user input is reflected in the response, allowing arbitrary JavaScript execution.

Impact

Attackers can inject malicious JavaScript through the langcode parameter in help pages, potentially stealing user credentials, session cookies, or executing unauthorized actions.

Remediation

Upgrade to Yonyou UFIDA ERP-NC version 5.1 or later that properly sanitizes the langcode parameter.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2025xsserp-ncufidayonyouvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:yonyou:ufida_erp-nc:5.0:*:*:*:*:*:*:*
FOFA: icon_hash="1085941792"

Source: ProjectDiscovery

References

4