jshERP versions 3.5 and earlier are affected by a stored...
Moderate severity
Unreviewed
Published
Dec 12, 2025
to the GitHub Advisory Database
•
Updated Dec 12, 2025
Description
Published by the National Vulnerability Database
Dec 12, 2025
Published to the GitHub Advisory Database
Dec 12, 2025
Last updated
Dec 12, 2025
jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to upload PDF files containing XSS payloads. Additionally, these PDF files can be accessed via static URLs, making them accessible to all users.
References