CVE-2025-51742

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the search query parameter directly to parseObject(), introducing a Fastjson deserialization vulnerability that can lead to RCE via JDBC payloads.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jishenghua:jsherp:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-11-25 20:15

Updated : 2025-12-02 15:38


NVD link : CVE-2025-51742

Mitre link : CVE-2025-51742

CVE.ORG link : CVE-2025-51742


JSON object : View

Products Affected

jishenghua

  • jsherp
CWE
CWE-502

Deserialization of Untrusted Data