CVE-2025-9568: Sun.net Ehrd Ctms

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

Affected products

  • Sun.net Ehrd Ctms: affected versions not specified

Published 2025-09-01. Last modified 2026-09-30.