Impact
The vulnerability is an authorization bypass in the userBusiness CRUD endpoints of jshERP. It allows any authenticated user to create, modify or delete authorization-relation rows without performing privilege checks. This flaw can be used to alter user‑role mappings, remove access from other accounts, or change role‑function relationships for any user within a tenant, effectively escalating privileges and compromising the integrity of access controls.
Affected Systems
The affected product is jshERP, released by jishenghua. The flaw exists in all versions through 3.6. Users running any of these versions are susceptible.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation yet. The likely attack vector is an authenticated user accessing the vulnerable CRUD endpoints, as there is no mention of unauthenticated exploitation. Exploitation requires authentication and relies on the lack of proper authorization checks, making it feasible for an attacker with legitimate credentials to manipulate access controls.
OpenCVE Enrichment