CVE-2025-9568: Sun.net Ehrd Ctms
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
Affected products
- Sun.net Ehrd Ctms: affected versions not specified
Published 2025-09-01. Last modified 2026-09-30.