Jishenghua

Jsherp

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 29.01.2026 13:32:06
  • Zuletzt bearbeitet 13.02.2026 20:43:37

A vulnerability was found in jishenghua jshERP up to 3.6. The impacted element is the function install of the file /jshERP-boot/plugin/installByPath of the component com.gitee.starblues.integration.operator.DefaultPluginOperator. The manipulation of ...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 28.01.2026 23:02:07
  • Zuletzt bearbeitet 09.02.2026 16:21:03

A vulnerability was identified in jishenghua jshERP up to 3.6. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/plugin/uploadPluginConfigFile of the component PluginController. Such manipulation of the argument conf...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 28.01.2026 22:02:06
  • Zuletzt bearbeitet 09.02.2026 16:58:44

A security vulnerability has been detected in jishenghua jshERP up to 3.6. The impacted element is the function getBillItemByParam of the file /jshERP-boot/depotItem/importItemExcel of the component com.jsh.erp.datasource.mappers.DepotItemMapperEx. T...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 12.12.2025 16:15:45
  • Zuletzt bearbeitet 19.12.2025 20:15:13

jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to upload PDF files containing XSS payloads. Additionally, these PDF files can be accessed via static URLs, making them accessible to all ...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 12.12.2025 00:00:00
  • Zuletzt bearbeitet 19.12.2025 20:15:34

jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the /msg/add endpoint.

  • EPSS 0.06%
  • Veröffentlicht 25.11.2025 00:00:00
  • Zuletzt bearbeitet 02.12.2025 14:45:35

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjson deserialization attacks.

  • EPSS 0.06%
  • Veröffentlicht 25.11.2025 00:00:00
  • Zuletzt bearbeitet 02.12.2025 14:56:09

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization attacks.

  • EPSS 0.06%
  • Veröffentlicht 25.11.2025 00:00:00
  • Zuletzt bearbeitet 02.12.2025 14:57:35

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserialization attacks.

  • EPSS 0.06%
  • Veröffentlicht 25.11.2025 00:00:00
  • Zuletzt bearbeitet 02.12.2025 15:13:31

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to fastjson deserialization attacks.

  • EPSS 0.06%
  • Veröffentlicht 25.11.2025 00:00:00
  • Zuletzt bearbeitet 02.12.2025 15:38:50

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the search query parameter directly to parseObject(), introducing a Fastjson deserialization vulnerability that can lead to RCE via J...