The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
Metrics
Affected Vendors & Products
References
History
Tue, 02 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Sep 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sunnet
Sunnet ehrd Ctms |
|
| Vendors & Products |
Sunnet
Sunnet ehrd Ctms |
Mon, 01 Sep 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Title | Sunnet|eHRD CTMS - Reflected Cross-site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published: 2025-09-01T02:32:27.215Z
Updated: 2025-09-02T20:44:59.666Z
Reserved: 2025-08-28T05:43:06.558Z
Link: CVE-2025-9567
Updated: 2025-09-02T20:44:54.645Z
Status : Awaiting Analysis
Published: 2025-09-01T03:15:32.337
Modified: 2025-09-02T15:55:25.420
Link: CVE-2025-9567
No data.