Stored XSS Vulnerability in jshERP Product by Jishenghua
CVE-2025-67341

4.6MEDIUM

Key Information:

Vendor

Jishenghua

Status
Vendor
CVE Published:
12 December 2025

What is CVE-2025-67341?

The jshERP application is vulnerable to a stored XSS attack due to improper handling of uploaded PDF files. Attackers can inject XSS payloads into these PDF files, which can be accessed through static URLs. Consequently, any user who accesses these URLs could be exposed to the malicious scripts. This vulnerability highlights the importance of robust input validation and security measures when handling file uploads in web applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.