CVE-2025-51744
- EPSS 0.41%
- Veröffentlicht 25.11.2025 00:00:00
- Zuletzt bearbeitet 02.12.2025 14:57:35
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserialization attacks.
CVE-2025-51743
- EPSS 0.41%
- Veröffentlicht 25.11.2025 00:00:00
- Zuletzt bearbeitet 02.12.2025 15:13:31
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to fastjson deserialization attacks.
CVE-2025-51742
- EPSS 0.41%
- Veröffentlicht 25.11.2025 00:00:00
- Zuletzt bearbeitet 02.12.2025 15:38:50
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the search query parameter directly to parseObject(), introducing a Fastjson deserialization vulnerability that can lead to RCE via J...
CVE-2025-60800
- EPSS 0.29%
- Veröffentlicht 28.10.2025 00:00:00
- Zuletzt bearbeitet 06.11.2025 18:44:16
Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request.
CVE-2025-60801
- EPSS 0.42%
- Veröffentlicht 24.10.2025 00:00:00
- Zuletzt bearbeitet 05.11.2025 21:06:25
jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function.
CVE-2025-55371
- EPSS 0.33%
- Veröffentlicht 21.08.2025 00:00:00
- Zuletzt bearbeitet 09.09.2025 19:11:54
Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing the getAllList method.
CVE-2025-55370
- EPSS 0.4%
- Veröffentlicht 21.08.2025 00:00:00
- Zuletzt bearbeitet 09.09.2025 19:11:44
Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the corresponding ID data by modifying the ID value.
CVE-2025-55368
- EPSS 0.4%
- Veröffentlicht 21.08.2025 00:00:00
- Zuletzt bearbeitet 09.09.2025 19:11:37
Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.
CVE-2025-55367
- EPSS 0.33%
- Veröffentlicht 21.08.2025 00:00:00
- Zuletzt bearbeitet 09.09.2025 19:11:20
Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.
CVE-2025-55366
- EPSS 0.33%
- Veröffentlicht 21.08.2025 00:00:00
- Zuletzt bearbeitet 09.09.2025 19:11:30
Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords and execute a horizontal privilege escalation attack.