VYPR
Unrated severityNVD Advisory· Published Feb 13, 2023· Updated Mar 21, 2025

CVE-2023-25241

CVE-2023-25241

Description

bgERP v22.31 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

bgERP v22.31 contains a reflected XSS vulnerability in the Search parameter, allowing attackers to execute arbitrary JavaScript in victims' browsers.

## Vulnerability bgERP version 22.31 suffers from a reflected cross-site scripting (XSS) vulnerability in the Search parameter of the /Portal/Show endpoint [2]. An attacker can inject arbitrary HTML and JavaScript via this parameter, which is reflected in the page without proper sanitization.

Exploitation

An attacker can craft a malicious URL containing a payload in the Search parameter and trick a logged-in user into clicking it [2]. No authentication is required to trigger the reflection, but the victim must be authenticated for the attack to leverage their session. The PoC URL demonstrates injecting an anchor tag with an image source that triggers a request to an attacker-controlled server.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser, potentially stealing session cookies, performing actions on behalf of the user, or defacing the page [2]. This can lead to full account compromise and data exposure.

Mitigation

As of the available references, no official patch has been released. Users should sanitize user input in the Search parameter, implement Content Security Policy headers, and consider upgrading to a newer version if available. The vendor may have addressed this in later releases, but no specific fixed version is mentioned.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • bgERP/bgERPdescription
  • bgERP/bgERPllm-create
    Range: v22.31

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.