Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22275 | A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component Account Handler. The manipulation of the argument ID leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 30 Jul 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jishenghua
Jishenghua jsherp |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:jishenghua:jsherp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jishenghua
Jishenghua jsherp |
Tue, 22 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Jul 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component Account Handler. The manipulation of the argument ID leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Title | jshERP Account delete improper authorization | |
| Weaknesses | CWE-266 CWE-285 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-07-22T13:27:57.463Z
Reserved: 2025-07-21T07:49:42.333Z
Link: CVE-2025-7947
Updated: 2025-07-22T13:27:47.958Z
Status : Analyzed
Published: 2025-07-22T01:15:22.820
Modified: 2025-07-30T15:44:51.797
Link: CVE-2025-7947
No data.
OpenCVE Enrichment
No data.
EUVD