CVE-2025-55367
EUVD-2025-2542621.08.2025, 14:15
Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jishenghua | jsherp | 3.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration