S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jul 17, 2025

CVE-2025-2711 Scanner

CVE-2025-2711 Scanner - Cross-Site Scripting (XSS) vulnerability in Yonyou UFIDA ERP-NC

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-2711
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been classified as problematic. Affected is an unknown function of the file /help/systop.jsp. The manipulation of the argument langcode leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Attack Vector
Network
Privileges Req.
None
User Interaction
P
Affected
UFIDA ERP-NCby Yonyou
5.0
Updated Aug 22, 2026View on NVD →
Detail

Yonyou UFIDA ERP-NC is a comprehensive Enterprise Resource Planning system widely used by businesses to optimize and streamline their operations. It is typically used by large and medium-sized enterprises in various industries, including finance, manufacturing, and supply chain management, to integrate and manage business processes across functions. Companies choose ERP-NC to increase efficiency, reduce costs, and gain insights into their business operations through consolidated data. The system comprises modules that cover areas such as finance, human resources, procurement, and logistics, allowing for customizable configurations to meet specific business needs. Users range from IT staff responsible for implementation and maintenance to department heads and employees who utilize the system's functionalities for daily operations. The broad usage of ERP-NC makes it crucial for maintaining data security and privacy across the organization.

Cross-Site Scripting (XSS) is a common vulnerability affecting web applications, where malicious scripts are executed in another user's browser. In the case of Yonyou UFIDA ERP-NC, this vulnerability arises from unsanitized inputs being used in the system's help JSP files. Attackers can leverage this flaw by injecting malicious scripts that execute within the context of the victim's session. This could result in the compromise of user accounts, theft of cookies, or unauthorized actions performed on the user's behalf. The vulnerability specifically affects the langcode parameter, which does not properly sanitize user input before rendering it on the client side. XSS attacks can be particularly damaging in enterprise environments as they can propagate unauthorized access and data breaches.

The vulnerability lies in the /help/systop.jsp and /help/top.jsp files within Yonyou UFIDA ERP-NC version 5.0. The affected parameter, langcode, is not adequately validated for dangerous characters or script tags, thereby allowing attackers to inject client-side scripts. Exploiting this vulnerability entails crafting a malicious request that triggers JavaScript execution when accessed by victims through their web browsers. The identified payloads demonstrate this by using an SVG tag with an onload event handler designed to alert the document domain. A key technical detail is that this payload ensures detection by targeting behaviors indicative of unsanitized content rendering, proving the response surface susceptible to manipulation.

When exploited, this XSS vulnerability can have severe implications for businesses relying on Yonyou UFIDA ERP-NC. Possible effects include unauthorized access to sensitive data, such as user credentials, through session hijacking, where attackers gain control over users' browsers. Attackers could also inject misleading content or redirect users to malicious sites, leading to further security breaches. Furthermore, if an attacker gains administrative access, they could alter system settings or extract confidential business data, disrupting operations. The financial and reputational damage from such attacks can be extensive, emphasizing the need for prompt remediation and effective security measures.

REFERENCES

Solution Advice
  • Update Yonyou UFIDA ERP-NC to the latest version to patch known vulnerabilities.
  • Implement proper input validation mechanisms to ensure that user input is thoroughly sanitized before processing.
  • Utilize output encoding to prevent the rendering of injected scripts in the browser.
  • Enable Content Security Policy (CSP) headers to restrict the execution of unauthorized scripts in the application.
  • Conduct regular security audits and penetration testing to identify and mitigate similar vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.