CVE-2024-24000
Published Feb 6, 2024jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into…
Vendor/product archive
2 CVEs tagged to huaxiaerp / jsherp — 1 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into…
Incorrect Access Control vulnerability in jshERP V3.3 allows attackers to obtain sensitive information via the doFilter function.