CVE-2025-9568

The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sun.net:ehrd_ctms:-:*:*:*:*:*:*:*

History

25 Sep 2025, 14:18

Type Values Removed Values Added
First Time Sun.net ehrd Ctms
CPE cpe:2.3:a:sun.net:corporate_training_management_system:-:*:*:*:*:*:*:* cpe:2.3:a:sun.net:ehrd_ctms:-:*:*:*:*:*:*:*

24 Sep 2025, 18:29

Type Values Removed Values Added
CPE cpe:2.3:a:sun.net:corporate_training_management_system:-:*:*:*:*:*:*:*
References () https://www.twcert.org.tw/en/cp-139-10357-7de41-2.html - () https://www.twcert.org.tw/en/cp-139-10357-7de41-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-10356-ea431-1.html - () https://www.twcert.org.tw/tw/cp-132-10356-ea431-1.html - Third Party Advisory
First Time Sun.net
Sun.net corporate Training Management System

01 Sep 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-01 03:15

Updated : 2025-09-25 14:18


NVD link : CVE-2025-9568

Mitre link : CVE-2025-9568

CVE.ORG link : CVE-2025-9568


JSON object : View

Products Affected

sun.net

  • ehrd_ctms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')