Skip to main content

Vendor archive

huaxiaerp CVEs

Beta · best-effort

6 CVEs tagged to vendor huaxiaerp1 Critical, 0 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2024-24000

Published Feb 6, 2024

jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-0491

Published Jan 13, 2024

A vulnerability classified as problematic has been found in Huaxia ERP up to 3.1. Affected is an unknown function of the file src/main/java/com/jsh/erp/controller/UserController.j…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0490

Published Jan 13, 2024

A vulnerability was found in Huaxia ERP up to 3.1. It has been rated as problematic. This issue affects some unknown processing of the file /user/getAllList. The manipulation lead…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48894

Published Nov 30, 2023

Incorrect Access Control vulnerability in jshERP V3.3 allows attackers to obtain sensitive information via the doFilter function.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3826

Published Nov 2, 2022

A vulnerability was found in Huaxia ERP. It has been classified as problematic. This affects an unknown part of the file /depotHead/list of the component Retail Management. The ma…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3825

Published Nov 2, 2022

A vulnerability was found in Huaxia ERP 2.3 and classified as critical. Affected by this issue is some unknown functionality of the component User Management. The manipulation of…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1