Impact
The vulnerability is a flaw in the updateAccountHeadAndDetail function of the jshERP Financial Receipt Update Handler. It allows an attacker to perform actions without proper authorization, enabling unauthorized access to or modification of financial receipt records. The weakness aligns with improper privilege elevation and authorization failures.
Affected Systems
The affected product is jishenghua jshERP, versions up to 3.5. The specific source file is AccountHeadService.java located in the jshERP‑boot module. No version zero‑day patches are currently available from the vendor, and the project has not yet responded with a fix.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. An exploit has been released to the public; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be initiated remotely when an affected endpoint is reachable, and success would allow an attacker to bypass authorization controls to manipulate financial data.
OpenCVE Enrichment