ZeroHour

CVE-2025-55368

PoC ×2
CVSS 3.1
8.8 high
EPSS
<1%p32
Published
()
Modified
Description

Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.

Vendors
jishenghua
Products
jsherp
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.