ZeroHour

CVE-2025-55370

PoC
CVSS 3.1
8.8 high
EPSS
<1%p32
Published
()
Modified
Description

Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the corresponding ID data by modifying the ID value.

Vendors
jishenghua
Products
jsherp
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.