Jishenghua

Jsherp

39 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.23%
  • Veröffentlicht 06.10.2026 03:30:13
  • Zuletzt bearbeitet 06.10.2026 14:17:37

A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component Financial Receipt Update Handle...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 21.09.2026 18:16:19
  • Zuletzt bearbeitet 22.09.2026 20:43:58

jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks. Attackers can manipulate user-role...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 21.09.2026 18:16:18
  • Zuletzt bearbeitet 22.09.2026 20:43:58

jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object identifiers w...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 21.09.2026 18:16:17
  • Zuletzt bearbeitet 22.09.2026 20:43:58

jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete roles. Attackers can exploit the /role/update and /role/delete endpoints to escalate privileg...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 21.09.2026 18:16:16
  • Zuletzt bearbeitet 24.09.2026 23:19:22

jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration. Attackers can rewrite or delete tenant-wide settings covering company identit...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 21.09.2026 18:16:14
  • Zuletzt bearbeitet 22.09.2026 20:43:58

jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can iterate the primary key to enumerate and access sensitive tenant data ...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 21.09.2026 18:16:13
  • Zuletzt bearbeitet 22.09.2026 20:43:58

jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-permission definitions. Attackers can supply arbitrary roleId and btnStr parameters to overwrit...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 21.09.2026 18:16:12
  • Zuletzt bearbeitet 22.09.2026 20:43:58

jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5 password digests for any user. Attackers can request arbitrary user information by supplying user IDs to obtain passw...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 21.09.2026 18:16:11
  • Zuletzt bearbeitet 22.09.2026 20:43:58

jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's password. Attackers can submit a request with an arbitrary target user ID to reset that ac...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 21.09.2026 18:16:10
  • Zuletzt bearbeitet 24.09.2026 23:19:21

jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles. Attackers can send a POST request with type=UserRole, their own user ID, and a ...