Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-67344 1 Jishenghua 1 Jsherp 2025-12-19 4.6 Medium
jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the /msg/add endpoint.
CVE-2025-67341 1 Jishenghua 1 Jsherp 2025-12-19 4.6 Medium
jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to upload PDF files containing XSS payloads. Additionally, these PDF files can be accessed via static URLs, making them accessible to all users.