CVE-2024-24000: Huaxiaerp Jsherp
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into the upload path, resulting in arbitrary file uploads with controllable paths.
Affected products
- Huaxiaerp Jsherp: version 3.3 only
Published 2024-02-06. Last modified 2026-06-17.