Stored XSS Vulnerability in jshERP Product by Jishenghua
CVE-2025-67341
4.6MEDIUM
What is CVE-2025-67341?
The jshERP application is vulnerable to a stored XSS attack due to improper handling of uploaded PDF files. Attackers can inject XSS payloads into these PDF files, which can be accessed through static URLs. Consequently, any user who accesses these URLs could be exposed to the malicious scripts. This vulnerability highlights the importance of robust input validation and security measures when handling file uploads in web applications.
