CVE-2025-55367: Jishenghua Jsherp
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.
Affected products
- Jishenghua Jsherp: version 3.5 only
Published 2025-08-21. Last modified 2026-07-05.