CVE-2025-55368
EUVD-2025-2541721.08.2025, 14:15
Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jishenghua | jsherp | 3.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration