Skip to main content

Vendor/product archive

huaxiaerp / jsherp CVEs

Beta · best-effort

2 CVEs tagged to huaxiaerp / jsherp1 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2024-24000

Published Feb 6, 2024

jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-48894

Published Nov 30, 2023

Incorrect Access Control vulnerability in jshERP V3.3 allows attackers to obtain sensitive information via the doFilter function.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1