Impact
The vulnerability exists in the getBillItemByParam function of com.jsh.erp.datasource.mappers.DepotItemMapperEx. The barCodes argument is concatenated directly into an SQL statement without proper validation, allowing an attacker to inject malicious SQL. This can lead to the execution of arbitrary SQL queries against the database, as stated in the CVE description.
Affected Systems
The affected product is jishenghua jshERP, version 3.6 and all earlier releases. No specific sub‑product or build information is provided, so any installation of jshERP up to and including 3.6 is potentially vulnerable.
Risk and Exploitability
The CVSS score is 5.3, indicating a medium risk level. The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low probability of widespread exploitation. The description indicates that the attack can be launched remotely, likely via the importItemExcel web endpoint, but no further exploitation prerequisites are described.
OpenCVE Enrichment