Metrics
Affected Vendors & Products
No advisories yet.
Solution
Please refer to the aEnrich advisory to upgrade to version 6.8 or later and install the latest patches, or contact aEnrich customer service for assistance.
Workaround
No workaround given by the vendor.
Wed, 12 Nov 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aenrich
Aenrich a+hrd |
|
| Vendors & Products |
Aenrich
Aenrich a+hrd |
Wed, 12 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The a+HRD and a+HCM developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to upload files containing malicious JavaScript code, which will execute on the client side when a user is tricked into visiting a specific URL. | |
| Title | aEnrich|eHRD - Stored Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-11-12T14:48:29.059Z
Reserved: 2025-11-07T11:11:01.140Z
Link: CVE-2025-12872
Updated: 2025-11-12T14:48:23.148Z
Status : Awaiting Analysis
Published: 2025-11-12T08:15:41.970
Modified: 2025-11-12T16:19:12.850
Link: CVE-2025-12872
No data.
OpenCVE Enrichment
Updated: 2025-11-12T22:12:41Z