ZeroHour

CVE-2025-55367

PoC ×2
CVSS 3.1
5.3 medium
EPSS
<1%p24
Published
()
Modified
Description

Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.

Vendors
jishenghua
Products
jsherp
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.