CVE-2025-55371
21.08.2025, 15:15
Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing the getAllList method.Enginsight
Vendor | Product | Version |
---|---|---|
jishenghua | jsherp | 3.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration