Filtered by vendor Huaxiaerp
Subscriptions
Filtered by product Jsherp
Subscriptions
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-24000 | 1 Huaxiaerp | 1 Jsherp | 2024-11-21 | 9.8 Critical |
jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into the upload path, resulting in arbitrary file uploads with controllable paths. | ||||
CVE-2023-48894 | 1 Huaxiaerp | 1 Jsherp | 2024-11-21 | 6.5 Medium |
Incorrect Access Control vulnerability in jshERP V3.3 allows attackers to obtain sensitive information via the doFilter function. |
Page 1 of 1.