CNNVD-202507-1821 Information

CNNVD ID

CNNVD-202507-1821

CVE-2025-7566

  • CNNVD Published: 2025-07-14

Description (Chinese)

jshERP(华夏ERP)是中国季圣华个人开发者的一款国产 ERP 系统。 jshERP 3.5及之前版本存在路径遍历漏洞,该漏洞源于文件SystemConfigController.java中参数Title操作不当,可能导致路径遍历攻击。

Description (English)

Jsherp (Wahsha ERP) is a nationally produced ERP system for Chinese personal developers in Zhi Sanhua. JsheRP 3.5 and previous versions have path-to-path loopholes, which stem from the inappropriate operation of the parameter Title in the SystemConfigController.java, which may lead to path-to-path attacks.

Hazard Level

High

Vulnerability Type

路径遍历

Affected Vendor

Live Support

Published

2025-07-14

Last Modified

2026-02-24

References

https://github.com/ShenxiuSec/cve-proofs/blob/main/POC-20250630-01.md https://github.com/ShenxiuSec/cve-proofs/blob/main/POC-20250630-01.md#steps-to-reproduce https://vuldb.com/?ctiid.316264 https://vuldb.com/?id.316264 https://vuldb.com/?submit.606784

Share on: