VendorsJishenghuajsherp3.5
Vulnerabilities

Jishenghua Jsherp 3.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2025-55368
Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.
Published 2025-08-21 · Modified
8.8EPSS 0.004
CVE-2025-55370
Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the corresponding ID data by modifying the ID value.
Published 2025-08-21 · Modified
8.8EPSS 0.004
CVE-2025-8839
jshERP Endpoint addUser improper authorization
Published 2025-08-11 · Analyzed
8.8EPSS 0.003
CVE-2025-8840
jshERP Endpoint deleteBatch improper authorization
Published 2025-08-11 · Analyzed
5.5EPSS 0.004
CVE-2025-55366
Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords and execute a horizontal privilege escalation attack.
Published 2025-08-21 · Modified
5.3EPSS 0.003
CVE-2025-55367
Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.
Published 2025-08-21 · Modified
5.3EPSS 0.003
CVE-2025-55371
Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing the getAllList method.
Published 2025-08-21 · Modified
5.3EPSS 0.003