CVE-2025-60800
28.10.2025, 18:15
Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request.Enginsight
| Vendor | Product | Version |
|---|---|---|
| jishenghua | jsherp | 𝑥 < 2025-08-07 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration