CVE-2024-24000
06.02.2024, 16:15
jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into the upload path, resulting in arbitrary file uploads with controllable paths.Enginsight
Vendor | Product | Version |
---|---|---|
huaxiaerp | jsherp | 3.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration