VYPR
Vendor

jshERP

Products
1
CVEs
40
Across products
40
Status
Private

Products

1

Recent CVEs

40
View all 40 CVEs →
  • CVE-2025-51746CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjson deserialization attacks.

  • CVE-2025-51745CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization attacks.

  • CVE-2025-51744CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserialization attacks.

  • CVE-2025-51743CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to fastjson deserialization attacks.

  • CVE-2025-51742CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the search query parameter directly to parseObject(), introducing a Fastjson deserialization vulnerability that can lead to RCE via JDBC payloads.

  • CVE-2024-24003CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutMaterialCount() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can construct malicious payload…

  • CVE-2024-24004CriFeb 7, 2024
    risk 0.64cvss 9.8epss 0.01

    jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutDetail() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can construct malicious payload to…

  • CVE-2024-24002CriFeb 7, 2024
    risk 0.64cvss 9.8epss 0.01

    jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseResponseInfo getListWithStock() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can construct malicious payload to…

  • CVE-2024-24001CriFeb 7, 2024
    risk 0.64cvss 9.8epss 0.01

    jshERP v3.3 is vulnerable to SQL Injection. via the com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findallocationDetail() function of jshERP which allows an attacker to construct malicious payload to bypass jshERP's protection mechanism.

  • CVE-2024-24000CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.01

    jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into the upload path, resulting in arbitrary file uploads with controllable paths.

  • CVE-2026-94411HigSep 21, 2026
    risk 0.57cvss 8.8epss 0.01

    jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles. Attackers can send a POST request with type=UserRole, their own user ID, and a role ID list to escalate from…

  • CVE-2025-55370HigAug 21, 2025
    risk 0.57cvss 8.8epss 0.00

    Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the corresponding ID data by modifying the ID value.

  • CVE-2025-55368HigAug 21, 2025
    risk 0.57cvss 8.8epss 0.00

    Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.

  • CVE-2025-60801HigOct 24, 2025
    risk 0.53cvss 8.2epss 0.00

    jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function.

  • CVE-2026-94501HigSep 21, 2026
    risk 0.50cvss 8.8epss 0.01

    jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks. Attackers can manipulate user-role mappings and access controls…

  • CVE-2026-94412HigSep 21, 2026
    risk 0.50cvss 8.8epss 0.01

    jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's password. Attackers can submit a request with an arbitrary target user ID to reset that account's password to a known…

  • CVE-2025-60800HigOct 28, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request.

  • CVE-2026-94497HigSep 21, 2026
    risk 0.47cvss 8.3epss 0.00

    jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object identifiers without authorization checks.

  • CVE-2026-94496HigSep 21, 2026
    risk 0.47cvss 8.3epss 0.00

    jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete roles. Attackers can exploit the /role/update and /role/delete endpoints to escalate privileges, change data visibility to…

  • CVE-2023-48894MedNov 30, 2023
    risk 0.42cvss 6.5epss 0.01

    Incorrect Access Control vulnerability in jshERP V3.3 allows attackers to obtain sensitive information via the doFilter function.