CVE-2025-7947
- EPSS 0.07%
- Veröffentlicht 22.07.2025 00:32:05
- Zuletzt bearbeitet 30.07.2025 15:44:51
A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component Account Handler. The manipulation of the argument ID leads to improper authorization. It is possible ...
CVE-2025-7566
- EPSS 0.28%
- Veröffentlicht 14.07.2025 03:02:05
- Zuletzt bearbeitet 06.11.2025 18:59:22
A vulnerability has been found in jshERP up to 3.5 and classified as critical. This vulnerability affects the function exportExcelByParam of the file /src/main/java/com/jsh/erp/controller/SystemConfigController.java. The manipulation of the argument ...
CVE-2024-24003
- EPSS 0.1%
- Veröffentlicht 08.02.2024 02:15:07
- Zuletzt bearbeitet 08.05.2025 19:15:58
jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutMaterialCount() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker ca...
CVE-2024-24001
- EPSS 0.06%
- Veröffentlicht 07.02.2024 00:15:56
- Zuletzt bearbeitet 15.05.2025 20:15:45
jshERP v3.3 is vulnerable to SQL Injection. via the com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findallocationDetail() function of jshERP which allows an attacker to construct malicious payload to bypass jshERP's pr...
CVE-2024-24004
- EPSS 0.12%
- Veröffentlicht 07.02.2024 00:15:56
- Zuletzt bearbeitet 21.11.2024 08:58:48
jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutDetail() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can const...
CVE-2024-24002
- EPSS 0.13%
- Veröffentlicht 07.02.2024 00:15:56
- Zuletzt bearbeitet 21.11.2024 08:58:48
jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseResponseInfo getListWithStock() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can const...