Impact
A remote attacker can supply a crafted platformValue parameter to the insertPlatformConfig endpoint, causing the application to send an HTTP request to an arbitrary target server. This server‑side request forgery can expose internal endpoints, access restricted resources, or exfiltrate sensitive data. The flaw is an input validation failure (CWE‑918) that permits an attacker to dictate the destination of outbound requests.
Affected Systems
The vulnerability affects the jishenghua jshERP platform, specifically all installations using version 3.6 and earlier. The affected component is the PlatformConfigService class in the platformConfig Add Endpoint module, which is part of the jshERP application bundle.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate impact, and although the EPSS score is currently unavailable, the exploit has been published and can be performed from a remote host. Because the vendor has not released a fix and the issue remains unpatched, the risk remains. The lack of KEV listing does not diminish the likelihood that this vulnerability could be abused in targeted attacks.
OpenCVE Enrichment