CNNVD-202511-2703 Information

CNNVD ID

CNNVD-202511-2703

CVE-2025-51743

  • CNNVD Published: 2025-11-25

Description (Chinese)

jshERP(华夏ERP)是中国季圣华个人开发者的一款国产 ERP 系统。 jshERP 2.3.1版本存在安全漏洞,该漏洞源于materialCategory/addMaterialCategory端点容易受到Fastjson反序列化攻击。

Description (English)

Jsherp (Wahsha ERP) is a nationally produced ERP system for Chinese personal developers in Zhi Sanhua. The jsheRP 2.3.1 version has a security loophole, which stems from the vulnerability of the materialCategory/addMaterialCategory endpoint to a Fastjson back-serialized attack.

Hazard Level

Low

Vulnerability Type

其他

Affected Vendor

个人开发者

Published

2025-11-25

Last Modified

2026-02-24

References

https://blog.hackpax.top/jsh-erp2/ https://gist.github.com/Paxsizy/cd1557aeba8093a8650601c4dbffb6f9 https://gitee.com/jishenghua https://gitee.com/jishenghua/JSH_ERP https://access.redhat.com/security/cve/cve-2025-51743

Patch

https://github.com/jishenghua/jshERP/releases

Share on: