CVE-2025-55371
EUVD-2025-2549321.08.2025, 15:15
Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing the getAllList method.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jishenghua | jsherp | 3.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration