Jishenghua

Jsherp

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.07%
  • Veröffentlicht 22.07.2025 00:32:05
  • Zuletzt bearbeitet 30.07.2025 15:44:51

A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component Account Handler. The manipulation of the argument ID leads to improper authorization. It is possible ...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 14.07.2025 03:02:05
  • Zuletzt bearbeitet 06.11.2025 18:59:22

A vulnerability has been found in jshERP up to 3.5 and classified as critical. This vulnerability affects the function exportExcelByParam of the file /src/main/java/com/jsh/erp/controller/SystemConfigController.java. The manipulation of the argument ...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 08.02.2024 02:15:07
  • Zuletzt bearbeitet 08.05.2025 19:15:58

jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutMaterialCount() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker ca...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 07.02.2024 00:15:56
  • Zuletzt bearbeitet 15.05.2025 20:15:45

jshERP v3.3 is vulnerable to SQL Injection. via the com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findallocationDetail() function of jshERP which allows an attacker to construct malicious payload to bypass jshERP's pr...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 07.02.2024 00:15:56
  • Zuletzt bearbeitet 21.11.2024 08:58:48

jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutDetail() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can const...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 07.02.2024 00:15:56
  • Zuletzt bearbeitet 21.11.2024 08:58:48

jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseResponseInfo getListWithStock() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can const...