jishenghua jshERP
10 known vulnerabilities in jishenghua jshERP, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-105621 CVSS 2.1 low A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file…
- CVE-2026-94501 CVSS 8.7 high jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to…
- CVE-2026-94497 CVSS 8.7 high jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types…
- CVE-2026-94496 CVSS 8.7 high jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's…
- CVE-2026-94495 CVSS 7.1 high jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to…
- CVE-2026-94494 CVSS 5.3 medium jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the…
- CVE-2026-94414 CVSS 5.3 medium jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to…
- CVE-2026-94413 CVSS 7.1 high jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5…
- CVE-2026-94412 CVSS 8.7 high jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to…
- CVE-2026-94411 CVSS 8.7 high jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to…