Metrics
Affected Vendors & Products
No advisories yet.
Solution
Please refer to the aEnrich advisory to upgrade to version 6.8 or later and install the latest patches, or contact aEnrich customer service for assistance.
Workaround
No workaround given by the vendor.
Wed, 12 Nov 2025 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The a+HRD and a+HCM developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to upload files containing malicious JavaScript code, which will execute on the client side when a user is tricked into visiting a specific URL. | |
| Title | aEnrich|eHRD - Stored Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-11-12T07:47:11.458Z
Reserved: 2025-11-07T11:11:01.140Z
Link: CVE-2025-12872
No data.
Status : Received
Published: 2025-11-12T08:15:41.970
Modified: 2025-11-12T08:15:41.970
Link: CVE-2025-12872
No data.
OpenCVE Enrichment
No data.