Critical severity9.8NVD Advisory· Published Nov 25, 2025· Updated Jun 17, 2026
CVE-2025-51742
CVE-2025-51742
Description
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the search query parameter directly to parseObject(), introducing a Fastjson deserialization vulnerability that can lead to RCE via JDBC payloads.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- jishenghua/JSH_ERPdescription
Patches
Vulnerability mechanics
References
2- gist.github.com/Paxsizy/a40334ffa7f05c42bf0348833f830108nvdThird Party Advisory
- blog.hackpax.top/jsh-erp/nvdBroken Link
News mentions
0No linked articles in our index yet.