VYPR

jshERP

by jshERP

Source repositories

CVEs (31)

  • CVE-2025-55371MedAug 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing the getAllList method.

  • CVE-2025-55367MedAug 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.

  • CVE-2025-55366MedAug 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords and execute a horizontal privilege escalation attack.

  • CVE-2026-8320MedMay 11, 2026
    risk 0.31cvss 4.7epss 0.00

    A security vulnerability has been detected in jishenghua jshERP up to 3.6. This affects the function getUserByWeixinCode of the file jshERP-boot/src/main/java/com/jsh/erp/service/UserService.java of the component updatePlatformConfigByKey Endpoint. Such manipulation of the…

  • CVE-2025-7566MedJul 14, 2025
    risk 0.31cvss 4.7epss 0.01

    A vulnerability has been found in jshERP up to 3.5 and classified as critical. This vulnerability affects the function exportExcelByParam of the file /src/main/java/com/jsh/erp/controller/SystemConfigController.java. The manipulation of the argument Title leads to path…

  • CVE-2025-67344MedDec 12, 2025
    risk 0.30cvss 4.6epss 0.00

    jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the /msg/add endpoint.

  • CVE-2025-67341MedDec 12, 2025
    risk 0.30cvss 4.6epss 0.00

    jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to upload PDF files containing XSS payloads. Additionally, these PDF files can be accessed via static URLs, making them accessible to all users.

  • CVE-2026-1549MedJan 28, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in jishenghua jshERP up to 3.6. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/plugin/uploadPluginConfigFile of the component PluginController. Such manipulation of the argument configFile leads to path…

  • CVE-2025-7948MedJul 22, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic was found in jshERP up to 3.5. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/user/updatePwd. The manipulation leads to weak password recovery. The attack can be launched remotely. The exploit has…

  • CVE-2026-11469MedJun 8, 2026
    risk 0.24cvss 4.7epss 0.00

    A flaw has been found in jishenghua jshERP up to 3.6. Impacted is the function insertPlatformConfig of the file jshERP-boot/src/main/java/com/jsh/erp/service/PlatformConfigService.java of the component platformConfig Add Endpoint. Executing a manipulation of the argument…

  • CVE-2026-1588LowJan 29, 2026
    risk 0.18cvss 2.7epss 0.01

    A vulnerability was found in jishenghua jshERP up to 3.6. The impacted element is the function install of the file /jshERP-boot/plugin/installByPath of the component com.gitee.starblues.integration.operator.DefaultPluginOperator. The manipulation of the argument path results in…

Page 2 of 2