VendorsHuaxia ERPjsherp3.3
Vulnerabilities

Huaxia ERP Jsherp 3.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2024-24000
jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into the upload path, resulting in arbitrary file uploads with controllable paths.
Published 2024-02-06 · Modified
9.8EPSS 0.006
CVE-2023-48894
Incorrect Access Control vulnerability in jshERP V3.3 allows attackers to obtain sensitive information via the doFilter function.
Published 2023-11-30 · Modified
6.5EPSS 0.006