Impact
jshERP up to version 3.6 contains an authorization failure on the POST /userBusiness/updateBtnStr API. When an authenticated user supplies arbitrary roleId and btnStr parameters, the system writes the new button‑permission configuration for that role without validating the caller’s privileges. The result is that any user with valid credentials can overwrite the button permissions of any role, affecting the integrity of role‑based access control and enabling unauthorized actions within the application.
Affected Systems
The affected product is jishenghua’s jshERP. The vulnerability is reported for versions up to and including 3.6; no higher‑version data is available.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user within the same tenant, who can exploit the unsecured endpoint to modify role permissions. If successful, the attacker can effectively elevate privileges within the tenant by granting themselves or other roles access to functions that should be restricted. Given the lack of external exploitation requirement, the primary risk is insider or compromised account abuse.
OpenCVE Enrichment