Vulnerabilities (CVE)

Filtered by vendor Huaxiaerp Subscribe
Filtered by product Jsherp
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-24000 1 Huaxiaerp 1 Jsherp 2024-02-13 N/A 9.8 CRITICAL
jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into the upload path, resulting in arbitrary file uploads with controllable paths.
CVE-2023-48894 1 Huaxiaerp 1 Jsherp 2023-12-10 N/A 6.5 MEDIUM
Incorrect Access Control vulnerability in jshERP V3.3 allows attackers to obtain sensitive information via the doFilter function.