jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function.
References
| Link | Resource |
|---|---|
| https://fushuling.com/index.php/2025/08/17/%e7%bb%95%e8%bf%87%e8%a1%a5%e4%b8%81%ef%bc%8c%e5%86%8d%e6%ac%a1%e5%ae%9e%e7%8e%b0%e5%8d%8e%e5%a4%8ferp%e6%9c%aa%e6%8e%88%e6%9d%83rce%e5%b7%b2%e4%bf%ae%e5%a4%8d/ | Exploit Third Party Advisory |
| https://github.com/jishenghua/jshERP/issues/132 | Exploit Issue Tracking Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-10-24 16:26
Updated : 2025-11-05 21:06
NVD link : CVE-2025-60801
Mitre link : CVE-2025-60801
CVE.ORG link : CVE-2025-60801
JSON object : View
Products Affected
jishenghua
- jsherp
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
