CVE-2025-55371
21.08.2025, 15:15
Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing the getAllList method.Enginsight
| Vendor | Product | Version |
|---|---|---|
| jishenghua | jsherp | 3.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration