CNNVD-202511-2723 Information
Nov 25, 2025
cve
CNNVD ID
CNNVD-202511-2723
Related CVE
- CNNVD Published: 2025-11-25
Description (Chinese)
jshERP(华夏ERP)是中国季圣华个人开发者的一款国产 ERP 系统。 jshERP 2.3.1版本存在安全漏洞,该漏洞源于user/addUser端点容易受到Fastjson反序列化攻击。
Description (English)
Jsherp (Wahsha ERP) is a nationally produced ERP system for Chinese personal developers in Zhi Sanhua. There is a security loophole in the jsherp 2.3.1 version, which stems from the vulnerability of the user/addUser endpoint to a Fastjson anti-serialized attack.
Hazard Level
Low
Vulnerability Type
其他
Affected Vendor
个人开发者
Published
2025-11-25
Last Modified
2026-02-24
References
https://blog.hackpax.top/jsh-erp3/ https://gist.github.com/Paxsizy/cd1557aeba8093a8650601c4dbffb6f9 https://gitee.com/jishenghua https://gitee.com/jishenghua/JSH_ERP https://access.redhat.com/security/cve/cve-2025-51744
Patch
https://github.com/jishenghua/jshERP/releases
Share on: