CVE-2025-10386 | Yida ECMS Consulting Enterprise Management System 1.0 POST Request /login.do requestUrl cross site scripting (EUVD-2025-29105)
A vulnerability classified as problematic was found in Yida ECMS Consulting Enterprise Management System 1.0. This affects an unknown part of the file /login.do of the component POST Request Handler. The manipulation of the argument requestUrl results in cross site scripting.
This vulnerability is known as CVE-2025-10386. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.